PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106580 ImageMagick CVE debrief

ImageMagick versions prior to 7.1.2-31 and 6.9.13-56 contain a policy bypass vulnerability in the CUT encoder. This issue allows a crafted local encoding operation to read data that policy should deny and can also cause a crash. The vulnerability affects ImageMagick installations and can be exploited through crafted local encoding operations. Defenders should prioritize verifying and updating ImageMagick installations to prevent potential data exposure and crashes. The CUT encoder's policy bypass allows unauthorized data access and can lead to system crashes. Affected roles include defenders responsible for ImageMagick installations, security teams, and developers using ImageMagick

Vendor
ImageMagick
Product
Unknown
CVSS
MEDIUM 4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for ImageMagick installations, security teams, and developers using ImageMagick in their applications should be aware of this vulnerability and take necessary actions to prevent potential data exposure and crashes.

Why it matters

Defenders should prioritize verifying and updating ImageMagick installations to prevent potential data exposure and crashes. This vulnerability allows a crafted local encoding operation to read data that policy should deny and can also cause a crash. Affected roles include defenders responsible for ImageMagick installations, security teams, and developers using ImageMagick in their applications.

  • Potential data exposure due to policy bypass
  • Crash caused by crafted local encoding operation
  • Verification of ImageMagick installations and updates required
  • Enforcement of security policies for ImageMagick usage necessary

Technical summary

The CUT encoder in ImageMagick versions prior to 7.1.2-31 and 6.9.13-56 contains a policy bypass vulnerability. This issue allows a crafted local encoding operation to read data that policy should deny and can also cause a crash. The vulnerability is due to a missing security-policy check in the CUT encoder. Affected product deployments should be identified and updated to prevent potential data exposure and crashes. The vulnerability can be exploited through crafted local encoding operations, and defenders should review and enforce security policies for ImageMagick usage

Defensive priority

Defenders should prioritize verifying and updating ImageMagick installations to prevent potential data exposure and crashes.

Recommended defensive actions

  • Verify ImageMagick installations and update to versions 7.1.2-31 or 6.9.13-56 or later
  • Review and enforce security policies for ImageMagick usage
  • Monitor ImageMagick logs for potential exploitation attempts
  • Perform vulnerability scanning to identify exposed ImageMagick installations
  • Implement compensating controls for exposed systems while remediation is scheduled and verified
  • Review asset inventory to identify systems that may be affected by this vulnerability
  • Track exceptions and retest remediated assets to ensure the vulnerability is fully resolved

Evidence notes

The CVE record and source item provide details on the vulnerability, affected versions, and fixed versions. However, there is limited information on potential exploitation or victim impact. The vulnerability is confirmed in ImageMagick versions prior to 7.1.2-31 and 6.9.13-56. There are no known instances of exploitation, but defenders should verify and update their installations as a precaution. The source item and CVE record provide the primary evidence for this vulnerability. Additional information from other sources may be needed

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106580 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106580

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106580 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106580

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • ImageMagick: Policy Bypass in CUT encoder

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/106xxx/CVE-2026-106580.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r868-pmwh-fv2c

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ImageMagick/ImageMagick/commit/768bdd0dbb9a9ad743b6a6e557126b788b325970

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ImageMagick/ImageMagick6/commit/ad178e41fce2afa6be2b91fb4e7f41c4c5448117

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.