CVE-2026-106580: ImageMagick: Policy Bypass in CUT encoder

Published Oct 7, 2026
·
Updated

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, a missing security-policy check in the CUT encoder allows a crafted local encoding operation to read data that policy should deny and can also cause a crash. This issue is fixed in versions 7.1.2-31 and 6.9.13-56.

Affected Software

1 affected component
ImageMagick ImageMagick<7.1.2-31, <6.9.13-56

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ImageMagick to a version that resolves this vulnerability.

    Fixed in 7.1.2-31
  2. Upgrade

    Upgrade ImageMagick to a version that resolves this vulnerability.

    Fixed in 6.9.13-56

Event History

Oct 7, 2026
CVE Published
via MITRE·03:54 PM
Data Sourced
via MITRE·03:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Systems using ImageMagick versions earlier than 7.1.2-31 or 6.9.13-56 are affected when a local encoding operation can be made to use the CUT encoder. The issue requires local access or local control of the encoding operation.

2

What can an attacker achieve?

A crafted local encoding operation may read data that the configured ImageMagick security policy is intended to deny. It can also cause ImageMagick to crash, resulting in a local availability impact.

3

What should be done if patching cannot happen immediately?

Prevent untrusted or unauthorized local users and processes from performing CUT encoding operations, particularly where ImageMagick security policies are relied on to restrict data access. Upgrading to 7.1.2-31 or 6.9.13-56 is the documented fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203