Security Policy Bypass Vulnerability in ImageMagick by ImageMagick
CVE-2026-105083

1.8LOW

Key Information:

Vendor
CVE Published:
3 October 2026

What is CVE-2026-105083?

The vulnerability in ImageMagick allows attackers to bypass security policies by exploiting a flaw in the LoadPolicyCache function. This occurs when the policy.xml uses an alternate DOCTYPE that does not correctly terminate, causing the parser to ignore security rules. As a result, potentially harmful operations that should be restricted become permitted, posing a significant security risk to applications utilizing this software. Users of ImageMagick are advised to upgrade to versions 7.1.2-32 or 6.9.13-57 or later to mitigate this vulnerability.

Affected Version(s)

ImageMagick 7.0.0-0 < 7.1.2-32

ImageMagick 0 < 6.9.13-57

References

CVSS V4

Score:
1.8
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yanhaoxi
.