Low severity3.3NVD Advisory· Published Jul 11, 2026· Updated Jul 14, 2026
CVE-2026-61858
CVE-2026-61858
Description
ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process.
Affected products
4- osv-coords2 versionspkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Leap%2016.0
< 7.1.2.27-2.1+ 1 more
- (no CPE)range: < 7.1.2.27-2.1
- (no CPE)range: < 7.1.2.0-160000.12.1
<7.1.2-26+ 1 more
- (no CPE)range: <7.1.2-26
- cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*range: <6.9.13-51
Patches
Vulnerability mechanics
References
2News mentions
1- ImageMagick: Ten Vulnerabilities Disclosed Together, Affecting Memory Handling and File WritingVypr Intelligence · Jul 11, 2026