<Vulnerability name="CVE-2026-61858">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Low</ThreatSeverity>
    <PublicDate>2026-07-11T13:01:08</PublicDate>
    <Bugzilla id="2499370" url="https://bugzilla.redhat.com/show_bug.cgi?id=2499370" xml:lang="en:us">
ImageMagick: ImageMagick: Policy bypass allows unauthorized file writing via APNG encoder
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>3.3</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-22</CWE>
    <Details xml:lang="en:us" source="Mitre">
ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in ImageMagick. This vulnerability allows attackers to bypass configured policy restrictions through the APNG (Animated Portable Network Graphics) encoding process. By exploiting missing validation checks in the APNG encoder and external delegates, an attacker can write files to disallowed paths. This could lead to unauthorized file creation or modification, potentially impacting system integrity.
    </Details>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:6">
        <ProductName>Red Hat Enterprise Linux 6</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>ImageMagick</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7">
        <ProductName>Red Hat Enterprise Linux 7</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>ImageMagick</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-61858
https://nvd.nist.gov/vuln/detail/CVE-2026-61858
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v3j6-27vc-7pw2
https://www.vulncheck.com/advisories/imagemagick-before-26-policy-bypass-via-apng-encoder
    </References>
</Vulnerability>