CVE-2026-105823 — ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 lacks a security policy check in the CUT encoder, allowing configured security policies to be …
Description
ImageMagick before 6.9.13-56 and 7.x before 7.1.2-31 lacks a security policy check in the CUT encoder, allowing configured security policies to be bypassed. Attackers can supply crafted input processed by the CUT encoder to crash the application or leak sensitive data.
CVSS v4.0 base metrics
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XLow severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Local
Attack Vector
AC
High
Attack Complexity
AT
Present
Attack Requirements
PR
None
Privileges Required
UI
None
User Interaction
VC
Low
Confidentiality (Vulnerable System)
VI
None
Integrity (Vulnerable System)
VA
Low
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
References
Related threats
same CWE or vendorCVE-2026-107510 — An authenticated high privilege user can inject arguments in troubleshooting commands resulting in privilege escalation.
CVE-2026-107510 · 13h ago
CVE-2026-76281 — Improper Access Control.
CVE-2026-76281 · 1d ago
CVE-2026-76265 — In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, a us…
CVE-2026-76265 · 1d ago
CVE-2026-76498 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engi…
CVE-2026-76498 · 1d ago
CVE-2026-76463 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensiv…
CVE-2026-76463 · 1d ago
CVE-2026-76455 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive int…
CVE-2026-76455 · 1d ago