# CVE-2026-50278

## Summary

- **CVE ID:** CVE-2026-50278
- **Severity:** MEDIUM
- **CVSS Score:** 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
- **CWE:** CWE-125, CWE-190, CWE-704
- **Published:** Aug 21, 2026
- **Last Modified:** Aug 26, 2026

## Description

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 have a `CIccEmbedIO::Read8()` size_t underflow. The issue arises due to an embedded-profile read defect when parsing ICC profiles containing `icSigEmbeddedV5ProfileTag` data with `icSigEmbeddedProfileType` payloads. Version 2.3.2.1 patches the issue. No known workarounds are available.

## Affected Products

- InternationalColorConsortium — iccDEV (< 2.3.2.1)

## References

- [CNA](https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-7qjg-7qq4-c77j)
- [CNA](https://github.com/InternationalColorConsortium/iccDEV/issues/987)
- [CNA](https://github.com/InternationalColorConsortium/iccDEV/commit/002d1108c1bd674de0ac1b0abfa0162986f19086)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.25%
- **EPSS Percentile:** 15.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-09._