---
id: CVE-2026-86424
title: >-
  ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use
  (TOCTOU) vulnerability in the video decoder that allows attackers to bypass
  path policy write restrictions via symlink swaps
summary: >-
  ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use
  (TOCTOU) vulnerability in the video decoder that allows attackers to bypass
  path policy write restrictions via symlink swaps. An attacker can replace a
  symlin…
severity: low
cvss: 2.5
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-59
  - CWE-367
vendor: imagemagick
product: imagemagick
affected:
  - imagemagick < 6.9.13-55
  - 'imagemagick >= 7.0.0-0, < 7.1.2-30'
patched:
  - imagemagick 7.1.2-30
published: '2026-09-07'
updated: '2026-09-19'
sourceUpdated: '2026-09-19T15:17:06.227'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86424'
references:
  - url: >-
      https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9x6f-98x9-rx6g
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/imagemagick-before-7.1.2-30-path-traversal-via-toctou-symlink-race
    label: disclosure@vulncheck.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-86424.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-86424'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2529434'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-86424'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86424'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
  - cve.org
epss: 0.00141
epssPercentile: 0.02778
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T17:41:40.830618Z'
ingestedAt: '2026-09-08T20:10:03.179Z'
---

## Overview

ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink between policy validation (check-time) and the file write operation (use-time) to write to policy-denied locations.

## Affected

- `imagemagick < 6.9.13-55`
- `imagemagick >= 7.0.0-0, < 7.1.2-30`

## Remediation

Upgrade past the affected range:

- `imagemagick 7.1.2-30`

## Vendor advisories

- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7 · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-86424.json)
