Policy Bypass Vulnerability in ImageMagick Affects Various Versions
CVE-2026-93587

4.8MEDIUM

Key Information:

Vendor
CVE Published:
18 September 2026

What is CVE-2026-93587?

A policy bypass vulnerability has been identified in ImageMagick, specifically in versions prior to 7.1.2-31 and 6.9.13-56. This flaw resides in the PCD coder, where certain command line options allowed local users to exceed configured resource limits, enabling potential excessive memory allocation. This could lead to limited availability impacts. The vulnerability has been addressed in the latest versions, ensuring that resource limits are effectively enforced during operation.

Affected Version(s)

ImageMagick 0 < 7.1.2-31

ImageMagick 0 < 6.9.13-56

ImageMagick 7.1.2-31

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yanhaoxi
.