SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-61862

LOW · CVSS 2.9 EPSS 0.10% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

ImageMagick versions prior to 7.1.2-26 and 6.9.13-51 are susceptible to an information disclosure vulnerability that allows a single byte to be printed beyond the profile boundary when displaying non-printable profile values with the identify command in debug mode. This could potentially expose sensitive data inadvertently. Organizations using ImageMagick for image processing, particularly those with debug output enabled, should prioritize updating to mitigate this low-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-61862
Severity
LOW
CVSS
2.9
EPSS
0.10%

Original NVD Description

ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This behavior occurs when debug output is enabled.