PT-2026-60150 · Unknown · Imagemagick

·

CVE-2026-61859

·

Published

2026-07-15

·

Updated

2026-07-30

CVSS v4.0

4.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 7.1.2-26 ImageMagick versions 6.9.13-x prior to 6.9.13-51
Description A policy bypass exists in the -script operation due to missing security policy checks. This flaw allows the reading of files from paths that are otherwise restricted by the configured security policy.
Recommendations Update to version 7.1.2-26 or later. Update to version 6.9.13-51 or later.

Exploit

Fix

Link Following

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61859
ECHO-139A-8B8F-C124
GHSA-VGHG-5JRG-2398
JLSEC-2026-1065
OPENSUSE-SU-2026:11310-1
OPENSUSE-SU-2026:21426-1
SUSE-SU-2026:22861-1
SUSE-SU-2026:3193-1
SUSE-SU-2026:3194-1
SUSE-SU-2026:3219-1

Affected Products

Imagemagick