CVE-2026-86422

ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions. Attackers can swap symlinks between policy validation and file access to read or write policy-denied files.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-09-07 13:20

Updated : 2026-09-10 16:18


NVD link : CVE-2026-86422

Mitre link : CVE-2026-86422

CVE.ORG link : CVE-2026-86422


JSON object : View

Products Affected

imagemagick

  • imagemagick
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')