PT-2026-86788 · Imagemagick+1 · Imagemagick

·

CVE-2026-86422

·

Published

2026-09-07

·

Updated

2026-09-07

CVSS v3.1

3.3

Low

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions. Attackers can swap symlinks between policy validation and file access to read or write policy-denied files.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86422
GHSA-X8G2-7R3W-H44P

Affected Products

Imagemagick