Description
ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 lacks a security policy check in the CUT encoder, allowing configured security policies to be bypassed. Attackers can supply crafted input processed by the CUT encoder to crash the application or leak sensitive data.
Published: 2026-10-08
Score: 2.1 Low
EPSS: n/a
KEV: No
Impact: Policy bypass leading to possible crash or data leakage
Action: Apply patch
AI Analysis

Impact

ImageMagick implementations prior to version 6.9.13-56 and 7.x prior to 7.1.2-31 contain a missing security policy check in the CUT encoder. This flaw permits an attacker to supply specially crafted input processed by the CUT encoder to either crash the application or expose sensitive information that the policy would normally have prevented. The vulnerability is a form of over‑privileged operation and could be used to compromise the confidentiality or availability of systems that process untrusted image data.

Affected Systems

The issue affects ImageMagick’s core product. Versions before 6.9.13-56 and before 7.1.2-31 of the 7.x release series are affected. Any installation of these versions that uses the CUT encoder is vulnerable; secure or restricted deployments that disable this encoder are not at risk.

Risk and Exploitability

The published CVSS score of 2.1 indicates low severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Based on the description, exploitation requires an attacker to deliver malicious input that is processed through the CUT encoder. The likely attack vector is that an attacker could supply crafted images to any service that calls the CUT encoder to process the image, which could be in typical image‑processing pipelines or web services that accept user‑supplied images. Inferred from the description, the attacker does not need local privileges and remote exploitation is plausible if the ImageMagick instance is exposed through a network service.

Generated by OpenCVE AI on October 8, 2026 at 17:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ImageMagick to version 7.1.2-31 or later, or to 6.9.13-56 or later for the 6.x series.
  • If upgrade is not immediately possible, disable the CUT encoder in the configuration or apply a security policy that rejects operations involving the CUT encoder.
  • Enable detailed logging for the CUT encoder and monitor for abnormal image processing failures that may indicate exploitation attempts.

Generated by OpenCVE AI on October 8, 2026 at 17:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 lacks a security policy check in the CUT encoder, allowing configured security policies to be bypassed. Attackers can supply crafted input processed by the CUT encoder to crash the application or leak sensitive data.
Title ImageMagick before 7.1.2-31 Policy Bypass in CUT Encoder
First Time appeared Imagemagick
Imagemagick imagemagick
Weaknesses CWE-284
CPEs cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Vendors & Products Imagemagick
Imagemagick imagemagick
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L'}

cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Imagemagick Imagemagick
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T14:10:27.322Z

Reserved: 2026-10-05T21:59:09.590Z

Link: CVE-2026-105823

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T15:17:34.140

Modified: 2026-10-08T15:17:34.140

Link: CVE-2026-105823

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T17:30:17Z

Weaknesses