PT-2026-54857 · Unknown · Imagemagick

·

CVE-2026-55628

·

Published

2026-07-01

·

Updated

2026-07-30

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 7.1.2-26
Description The -concatenate operation lacks necessary policy checks. This flaw allows the software to read from and write to file paths that are explicitly disallowed by the security policy, enabling a policy bypass.
Recommendations Update to version 7.1.2-26.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55628
ECHO-DD51-36A7-172C
GHSA-82MP-VP5C-9PF7
JLSEC-2026-1041
OESA-2026-2853
OESA-2026-2854
OESA-2026-2855
OESA-2026-2856
OPENSUSE-SU-2026:11228-1
OPENSUSE-SU-2026:21391-1
SUSE-SU-2026:22829-1
SUSE-SU-2026:3192-1
SUSE-SU-2026:3193-1
SUSE-SU-2026:3194-1
SUSE-SU-2026:3219-1

Affected Products

Imagemagick