CVE-2026-61859: ImageMagick before 7.1.2-26 Policy Bypass via script operation
ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-26 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 6.9.13-51
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61859?
The severity of CVE-2026-61859 is medium with a score of 4.8.
How do I fix CVE-2026-61859?
To fix CVE-2026-61859, update ImageMagick to version 7.1.2-26 or later, or version 6.9.13-51 or later.
What does CVE-2026-61859 affect?
CVE-2026-61859 affects ImageMagick versions before 7.1.2-26 and 6.9.13-x before 6.9.13-51.
What is the impact of CVE-2026-61859?
CVE-2026-61859 allows a policy bypass via the -script operation, permitting reading files from restricted paths.
In what scenarios can CVE-2026-61859 be exploited?
CVE-2026-61859 can be exploited when ImageMagick is configured to process scripts without stringent security policy checks.