Junglewise Threat Intelligence

CVE-2026-61858: ImageMagick policy bypass in APNG encoder and external delegates

CVE-2026-61858 · Severity: low · CVSS 3.3 · Published 2026-07-11

Technologies: Magick.NET-Q16-OpenMP-arm64 (NuGet), Magick.NET-Q16-AnyCPU (NuGet), Magick.NET-Q16-HDRI-AnyCPU (NuGet), Magick.NET-Q8-x86 (NuGet), Magick.NET-Q8-AnyCPU (NuGet), Magick.NET-Q16-arm64 (NuGet), Magick.NET-Q16-OpenMP-x64 (NuGet), Magick.NET-Q16-HDRI-arm64 (NuGet), Magick.NET-Q16-HDRI-x86 (NuGet), Magick.NET-Q16-HDRI-x64 (NuGet), Magick.NET-Q8-OpenMP-arm64 (NuGet), Magick.NET-Q8-OpenMP-x64 (NuGet), ImageMagick, Magick.NET-Q16-x64 (NuGet), Magick.NET-Q8-arm64 (NuGet), Magick.NET-Q8-x64 (NuGet), Magick.NET-Q16-x86 (NuGet), Magick.NET-Q16-HDRI-OpenMP-arm64 (NuGet). Vendors: NuGet, ImageMagick.

Executive brief

ImageMagick, a widely used software suite for editing and converting images, contains a security flaw in how it handles certain animated image formats (APNG). This vulnerability allows a user with local access to bypass security policies and write files to restricted locations on the system. While the risk is categorized as low, it could potentially be used to overwrite sensitive configuration files or system data if the software is not updated.

Technical details

A policy bypass vulnerability exists in ImageMagick's APNG encoder and external delegates due to missing validation checks. The flaw is classified under CWE-59 (Improper Link Resolution) and CWE-862 (Missing Authorization), where the software fails to properly enforce configured security policies during the encoding process. An attacker with local access and low privileges can exploit this to write files to paths that should be restricted by ImageMagick's security policy. The issue is resolved in versions 7.1.2-26 and 6.9.13-51.

Affected products

  • ImageMagick ImageMagick < 7.1.2-26, < 6.9.13-51

Timeline

  • 2026-06-26: advisory: GitHub Security Advisory published by maintainers
  • 2026-07-11: disclosed: CVE published in NVD dataset

References

Related threats