CVE-2026-61858: ImageMagick before 7.1.2-26 Policy Bypass via APNG encoder
ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-26 - Compensating control
If immediate upgrade is not possible, restrict or sandbox ImageMagick usage to prevent it from writing to disallowed paths while the APNG encoder policy bypass is present.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61858?
CVE-2026-61858 has a low severity rating of 3.3.
How do I fix CVE-2026-61858?
To fix CVE-2026-61858, update ImageMagick to version 7.1.2-26 or later.
What does CVE-2026-61858 affect?
CVE-2026-61858 affects versions of ImageMagick prior to 7.1.2-26.
What is the impact of CVE-2026-61858?
CVE-2026-61858 allows attackers to bypass policy restrictions and write files to disallowed paths.
How can CVE-2026-61858 be exploited?
CVE-2026-61858 can be exploited through the APNG encoding process due to missing validation checks.