---
id: CVE-2026-86422
title: >-
  ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability
  in path policy enforcement on Windows that allows attackers to bypass read or
  write restrictions by exploiting symlink race conditions
summary: >-
  ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability
  in path policy enforcement on Windows that allows attackers to bypass read or
  write restrictions by exploiting symlink race conditions. Attackers can swap
  sym…
severity: low
cvss: 3.3
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N'
cwe:
  - CWE-59
  - CWE-367
vendor: imagemagick
product: imagemagick
affected:
  - imagemagick < 6.9.13-55
  - 'imagemagick >= 7.0.0-0, < 7.1.2-30'
patched:
  - imagemagick 7.1.2-30
published: '2026-09-07'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T16:18:02.537'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86422'
references:
  - url: >-
      https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-x8g2-7r3w-h44p
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-path-policy-toctou-symlink-race
    label: disclosure@vulncheck.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-86422.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-86422'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2529438'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-86422'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86422'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T14:19:00.678476Z'
epss: 0.00132
epssPercentile: 0.02302
ingestedAt: '2026-09-08T20:10:03.179Z'
---

## Overview

ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions. Attackers can swap symlinks between policy validation and file access to read or write policy-denied files.

## Affected

- `imagemagick < 6.9.13-55`
- `imagemagick >= 7.0.0-0, < 7.1.2-30`

## Remediation

Upgrade past the affected range:

- `imagemagick 7.1.2-30`

## Vendor advisories

- **Red Hat VEX** · Low · updated 2026-09-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-86422.json)
