Description
ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the parser consume the rest of the file, so no policy rules are applied and restricted operations become allowed.
Published: 2026-10-03
Score: 1.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: Security Policy Bypass
Action: Patch
AI Analysis

Impact

ImageMagick versions prior to 7.1.2-32 and 6.9.13-57 contain a vulnerability in the LoadPolicyCache function that allows an attacker to supply a policy.xml file with an alternate DOCTYPE. The parser incorrectly handles a DOCTYPE that does not terminate with "]>", causing it to consume the remainder of the file and silently skip all defined security policy rules. As a result, operations that are normally restricted by the policy become allowed, creating a clear path for an attacker to perform unintended actions such as accessing or modifying files, executing commands, or otherwise violating the intended security posture.

Affected Systems

The affected vendor is ImageMagick and the product is ImageMagick. Versions affected are all releases prior to 7.1.2-32 and all releases prior to 6.9.13-57, meaning almost all older releases of the software are susceptible unless upgraded.

Risk and Exploitability

The CVSS score of 1.8 places this issue in the low severity range, and the EPSS score is not documented, indicating a low exploitation probability as of the latest data. It is not listed in the CISA KEV catalog. The vulnerability is likely to be exploited locally by an attacker who can influence image processing via a crafted policy.xml file, though remote exploitation could be possible if an untrusted image is processed by a publicly exposed service. The evidence available suggests the attack vector is not high and the impact is limited to policy-bypass rather than direct remote code execution.

Generated by OpenCVE AI on October 3, 2026 at 13:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ImageMagick to version 7.1.2‑32 or newer, or to 6.9.13‑57 or newer, to ensure LoadPolicyCache correctly validates DOCTYPE.
  • Verify that policy.xml files in use employ the standard DOCTYPE and do not rely on alternate definitions that could be abused.
  • If an upgrade is not yet feasible, restrict or disable image processing of files from untrusted sources until the platform is patched.

Generated by OpenCVE AI on October 3, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1286
References
Metrics threat_severity

None

threat_severity

Low


Sat, 03 Oct 2026 01:45:00 +0000

Type Values Removed Values Added
Description ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in ']>' makes the parser consume the rest of the file, so no policy rules are applied and restricted operations become allowed.
Title ImageMagick before 7.1.2-32 and 6.9.13-57 Security Policy Bypass via policy.xml DOCTYPE
First Time appeared Imagemagick
Imagemagick imagemagick
Weaknesses CWE-693
CPEs cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Vendors & Products Imagemagick
Imagemagick imagemagick
References
Metrics cvssV3_1

{'score': 3.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 1.8, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Imagemagick Imagemagick
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-03T01:11:12.822Z

Reserved: 2026-10-03T01:03:07.467Z

Link: CVE-2026-105083

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T02:17:18.170

Modified: 2026-10-03T02:17:18.170

Link: CVE-2026-105083

cve-icon Redhat

Severity : Low

Publid Date: 2026-10-03T01:11:12Z

Links: CVE-2026-105083 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T13:30:08Z

Weaknesses
  • CWE-1286

    Improper Validation of Syntactic Correctness of Input

  • CWE-693

    Protection Mechanism Failure