CVE-2026-86422: ImageMagick before 7.1.2-30 Path Policy TOCTOU Symlink Race
ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions. Attackers can swap symlinks between policy validation and file access to read or write policy-denied files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-30
Event History
Frequently Asked Questions
Which deployments are exposed?
The issue affects ImageMagick versions before 7.1.2-30 on Windows. Exposure depends on having path-policy read or write restrictions that an attacker can target.
What must an attacker be able to do to exploit this?
An attacker needs the ability to manipulate symlinks and win a race between path-policy validation and the subsequent file access. The CVSS vector also indicates local access, low privileges, high attack complexity, and user interaction are required.
What is the impact if exploitation succeeds?
An attacker may bypass configured path-policy restrictions to read or write files that the policy would otherwise deny. The supplied severity vector indicates low confidentiality and integrity impact, with no availability impact.
How can this be remediated?
Upgrade ImageMagick to version 7.1.2-30 or later. The provided information does not identify an alternative mitigation for systems that cannot be upgraded immediately.