PT-2026-2087 · Iccdev · Iccdev

Xsscx

·

Published

2026-01-07

·

Updated

2026-01-07

·

CVE-2026-21690

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions iccDEV versions prior to 2.3.1.2
Description iccDEV is a set of libraries and tools for interacting with International Color Consortium (ICC) color management profiles. A Type Confusion issue exists in the CIccTagXmlTagData::ToXml() function, impacting users who process ICC color profiles.
Recommendations Update to version 2.3.1.2 or later.

Exploit

Fix

Type Confusion

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-21690
GHSA-2F26-VH48-38G6

Affected Products

Iccdev