---
id: CVE-2026-61858
title: >-
  ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG
  encoder and external delegates due to missing validation checks
summary: >-
  ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG
  encoder and external delegates due to missing validation checks. Attackers can
  write files to disallowed paths by bypassing configured policy restrictions
  thr…
severity: low
cvss: 3.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-59
published: '2026-07-11'
updated: '2026-07-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-61858'
references:
  - url: >-
      https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v3j6-27vc-7pw2
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/imagemagick-before-26-policy-bypass-via-apng-encoder
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-07-12T00:16:39.341Z'
epss: 0.00246
epssPercentile: 0.16221
---

## Overview

ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
