Path Policy Vulnerability in ImageMagick for Windows
CVE-2026-86422

1LOW

Key Information:

Vendor
CVE Published:
7 September 2026

What is CVE-2026-86422?

ImageMagick versions prior to 7.1.2-30 exhibit a time-of-check to time-of-use (TOCTOU) vulnerability on Windows. This issue arises in the enforcement of path policies, allowing malicious actors to exploit symlink race conditions. By manipulating symlinks between the policy validation and subsequent file access, attackers can gain unauthorized read or write access to files that would otherwise be restricted by policy. This vulnerability poses significant risks, allowing unauthorized manipulation of sensitive files in environments utilizing ImageMagick.

Affected Version(s)

ImageMagick 0 < 7.1.2-30

ImageMagick 0 < 6.9.13-55

ImageMagick 7.1.2-30

References

CVSS V4

Score:
1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gb1dev
.