PT-2026-57445 · Unknown · Imagemagick

·

CVE-2026-61858

·

Published

2026-07-11

·

Updated

2026-08-24

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 7.1.2-26
Description A policy bypass exists in the APNG encoder and external delegates caused by missing validation checks. This allows attackers to bypass configured policy restrictions during the APNG encoding process to write files to disallowed paths.
Recommendations Update to version 7.1.2-26 or later.

Exploit

Fix

Missing Authorization

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61858
ECHO-574F-7DD6-DD6E
GHSA-V3J6-27VC-7PW2
JLSEC-2026-1064
OESA-2026-3057
OESA-2026-3058
OESA-2026-3059
OESA-2026-3060
OESA-2026-3061
OPENSUSE-SU-2026:11273-1
OPENSUSE-SU-2026:21391-1
SUSE-SU-2026:22829-1
SUSE-SU-2026:3193-1
SUSE-SU-2026:3194-1
SUSE-SU-2026:3219-1

Affected Products

Imagemagick