Path Policy Vulnerability in ImageMagick for Windows
CVE-2026-86422
1LOW
What is CVE-2026-86422?
ImageMagick versions prior to 7.1.2-30 exhibit a time-of-check to time-of-use (TOCTOU) vulnerability on Windows. This issue arises in the enforcement of path policies, allowing malicious actors to exploit symlink race conditions. By manipulating symlinks between the policy validation and subsequent file access, attackers can gain unauthorized read or write access to files that would otherwise be restricted by policy. This vulnerability poses significant risks, allowing unauthorized manipulation of sensitive files in environments utilizing ImageMagick.
Affected Version(s)
ImageMagick 0 < 7.1.2-30
ImageMagick 0 < 6.9.13-55
ImageMagick 7.1.2-30