PatchSiren cyber security CVE debrief
CVE-2026-86422 ImageMagick CVE debrief
ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows. This allows attackers to bypass read or write restrictions by exploiting symlink race conditions. The vulnerability affects ImageMagick installations on Windows systems, where attackers can swap symlinks between policy validation and file access to read or write policy-denied files. Defenders should assess exposure and prioritize updates to version 7.1.2-30 or later. The CVE record and NVD entry provide limited information about the vulnerability, with a CVSS score of 1 and severity of LOW.
- Vendor
- ImageMagick
- Product
- Unknown
- CVSS
- LOW 1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-07
- Original CVE updated
- 2026-09-07
- Advisory published
- 2026-09-07
- Advisory updated
- 2026-09-07
Who should care
Defenders responsible for ImageMagick installations on Windows systems should assess exposure and prioritize updates to version 7.1.2-30 or later. This includes verifying and updating ImageMagick installations, assessing exposure on Windows systems, and monitoring for potential attacks. Security teams and vulnerability management teams should also review the vulnerability and plan vendor-supported updates or mitigations through normal change control where
Why it matters
CVE-2026-86422 is a time-of-check-time-of-use vulnerability in ImageMagick on Windows that allows attackers to bypass read or write restrictions. Defenders should prioritize verifying and updating ImageMagick installations, assessing exposure on Windows systems, and monitoring for potential attacks.
- Verify and update ImageMagick installations to prevent potential symlink race condition attacks
- Assess exposure on Windows systems and prioritize updates for vulnerable installations
- Monitor for potential attacks exploiting this vulnerability
Technical summary
The vulnerability exists in ImageMagick before version 7.1.2-30 on Windows, allowing attackers to bypass read or write restrictions by exploiting symlink race conditions during path policy enforcement. This occurs when attackers swap symlinks between policy validation and file access to read or write policy-denied files. The vulnerability affects ImageMagick installations on Windows systems. Defenders should prioritize verifying and updating ImageMagick installations to version 7.1.2-30 or later, and assess exposure on Windows systems.
Defensive priority
Defenders should prioritize verifying and updating ImageMagick installations to version 7.1.2-30 or later, and assess exposure on Windows systems.
Recommended defensive actions
- Verify ImageMagick installations are up-to-date on Windows systems
- Assess exposure and prioritize updates for vulnerable installations
- Monitor for potential symlink race condition attacks on Windows
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability, with a CVSS score of 1 and severity of LOW. The vulnerability exists in ImageMagick before version 7.1.2-30 on Windows, allowing attackers to bypass read or write restrictions by exploiting symlink race conditions during path policy enforcement. Defenders should verify and update ImageMagick installations to version 7.1.2-30 or later, and assess exposure on Windows systems. The source detail is limited, and defenders should prioritize verifying and The
Sources and references
Verified primary and authoritative sources
-
CVE-2026-86422 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-86422
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-86422 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86422
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-x8g2-7r3w-h44p
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-path-policy-toctou-symlink-race
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.