ht_undo_impl in the library src/lib/OpenEXRCore/internal_ht.cpp of the component EXR File Handler. The manipulation results in integer overflow.This vulnerability is known as CVE-2026-39886. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.