CVE-2026-40385 is an unsigned 32-bit integer overflow vulnerability in libexif through version 0.6.25 affecting Nikon MakerNote handling, with impact limited to 32-bit systems. This vulnerability can be exploited by local attackers to trigger application crashes or leak sensitive information from memory. The vulnerability carries a CVSS score of 7.1 (HIGH) with a local attack vector requiring low complexity and user privileges but no interaction. The EPSS score of 0.0001 indicates minimal current exploit prevalence, and the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog, suggesting no active exploitation in the wild. Community attention appears limited given the inactive status on security hotlists, though the moderate FAUCET Risk Score of 47.0 indicates organizations should still prioritize patching 32-bit systems running affected versions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 0.6.25CPE match | cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:* | ||
<= 0.6.25CPE matchmatch criteria | cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.