CVE-2026-40386 is an integer underflow vulnerability in libexif through version 0.6.25 that affects the MakerNote decoding functionality for Fuji and Olympus image formats. This flaw could allow attackers to crash applications using libexif or extract sensitive information from memory. The vulnerability has a CVSS score of 7.1 (HIGH) with a local attack vector requiring low privileges and user interaction, presenting significant confidentiality and availability risks. As of the current assessment, there is no evidence of active exploitation in the wild, with an extremely low EPSS score of 0.00005, and the vulnerability does not appear on the Known Exploited Vulnerabilities list. Community attention remains limited given its inactive status on threat tracking lists, though the moderate FAUCET risk score of 47.0 warrants monitoring and timely patch deployment for systems processing untrusted image files.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 0.6.25CPE match | cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:* | ||
<= 0.6.25CPE matchmatch criteria | cpe:2.3:a:libexif_project:libexif:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.