Time-of-Check to Time-of-Use Vulnerability in ImageMagick by ImageMagick Studio LLC
CVE-2026-86424
2LOW
What is CVE-2026-86424?
A TOCTOU vulnerability in ImageMagick prior to version 7.1.2-30 and 6.9.13-55 allows attackers to exploit symlink swaps between the time of policy validation and the actual file write operation. This enables them to bypass restrictions that normally prevent writing to unauthorized locations, posing a significant security risk.
Affected Version(s)
ImageMagick 0 < 7.1.2-30
ImageMagick 0 < 6.9.13-55
ImageMagick 7.1.2-30