Arbitrary Code Execution Vulnerability in libtiff Affects Various Image Processing Applications
CVE-2026-52491

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-52491?

A vulnerability in libtiff allows attackers to execute arbitrary code through a flaw in the thumbnail generation component of the library. This can be exploited when handling specially crafted TIFF files, potentially leading to unauthorized actions and compromised systems. Users of libtiff are urged to review their applications and implement the recommended patches to mitigate this risk.

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.