CVE-2026-28666

In multiple functions of LocalImageResolver.java, there is a possible Remote Persistent Denial of Service due to a DNG image rendering check bypass. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-08 19:17

Updated : 2026-09-10 15:17


NVD link : CVE-2026-28666

Mitre link : CVE-2026-28666

CVE.ORG link : CVE-2026-28666


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization