ImageMagick TOCTOU Video Decoder Symlink Bypass (before 7.1.2-30/6.9.13-55)
CVE-2026-86424 Published on September 7, 2026
ImageMagick before 7.1.2-30 Path Traversal via TOCTOU Symlink Race
ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink between policy validation (check-time) and the file write operation (use-time) to write to policy-denied locations.
Vulnerability Analysis
CVE-2026-86424 is exploitable with local system access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
What is an insecure temporary file Vulnerability?
The software attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CVE-2026-86424 has been classified to as an insecure temporary file vulnerability or weakness.
Products Associated with CVE-2026-86424
Want to know whenever a new CVE is published for ImageMagick? stack.watch will email you.
Affected Versions
ImageMagick:- Before 7.1.2-30 is affected.
- Version 7.1.2-30 is unaffected.
- Before 6.9.13-55 is affected.
- Version 6.9.13-55 is unaffected.