CVE-2026-21692: iccDEV has Type Confusion in ToXmlCurve() at IccXML/IccLibXML/IccMpeXml.cpp
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in ToXmlCurve() at IccXML/IccLibXML/IccMpeXml.cpp. This vulnerability affects users of the iccDEV library who process ICC color profiles. Version 2.3.1.2 contains a patch. No known workarounds are available.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21692?
CVE-2026-21692 has a critical severity due to its Type Confusion vulnerability that can lead to security risks.
How do I fix CVE-2026-21692?
To fix CVE-2026-21692, update iccDEV to version 2.3.1.2 or later.
What are the potential impacts of CVE-2026-21692?
The potential impacts of CVE-2026-21692 include unexpected behavior and possible exploitation of the Type Confusion vulnerability.
Which versions of iccDEV are affected by CVE-2026-21692?
Versions of iccDEV prior to 2.3.1.2 are affected by CVE-2026-21692.
Is there a workaround for CVE-2026-21692?
There are currently no known workarounds for CVE-2026-21692; upgrading is the recommended solution.