{"id":"CVE-2026-52490","title":"An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c","summary":"An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-94","CWE-78"],"published":"2026-08-24","updated":"2026-09-09","sourceUpdated":"2026-09-09T16:03:22.897","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-52490","references":[{"url":"https://gist.github.com/okyfh/122c2d72e991a78c8af80a3af3be8671","label":"cve@mitre.org"},{"url":"https://gitlab.com/libtiff/libtiff/-/work_items/846","label":"cve@mitre.org"},{"url":"https://gitlab.com/libtiff/libtiff/-/work_items/846","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52490.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-52490"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2523148"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-52490"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-52490"},{"url":"https://access.redhat.com/errata/RHSA-2026:53467"},{"url":"https://access.redhat.com/errata/RHSA-2026:69095"}],"tags":["nvd","csaf","vex","red-hat","score-dispute"],"epss":0.0051,"epssPercentile":0.4097,"ingestedAt":"2026-09-09T16:14:05.515Z","vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","affected":["enterprise_linux 10","enterprise_linux 6","enterprise_linux 7","enterprise_linux 8","hardened_images"],"patched":["hardened_images"],"scores":{"nvd":9.8,"vendor":7.3},"slug":"CVE-2026-52490","body":"## Overview\n\nAn issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:53467** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53467)\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52490.json)\n- **RHSA-2026:69095** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8), Red Hat Enterprise Linux CRB (v. 8) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69095)","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}