CVE-2026-21686 is an Undefined Behavior vulnerability in the iccDEV library, specifically within the CIccTagLutAtoB::Validate() function, affecting versions prior to 2.3.1.2. This flaw impacts applications that process International Color Consortium (ICC) color management profiles using the iccDEV library. Rated 7.1 HIGH on the CVSS scale, this vulnerability can be exploited remotely with low attack complexity, requiring user interaction. While confidentiality is not impacted, it carries a potential for low integrity and high availability impact. Currently, there is no evidence of active exploitation, nor is exploit code publicly available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.1.1CPE matchmatch criteria | cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.