Execution Flaw in MathWorks Simulink Allows Concealed Code Execution
CVE-2026-105043

3.6LOW

Key Information:

Vendor

Mathworks

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-105043?

MathWorks Simulink versions prior to R2026b have a security flaw where a specially crafted .slx file can execute code via blocks that are hidden from view in the Simulink Editor. These concealed blocks pose a significant risk as they can trigger unintended actions, potentially compromising the integrity and security of the software.

Affected Version(s)

Simulink 0

References

CVSS V3.1

Score:
3.6
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.