CVE-2026-86424
lowCVSS v3 Base Score
2.5
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Characteristics
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Confidentiality
None
Integrity
Low
Availability
None
Published: September 7, 2026 (3 days ago)
Last Modified: September 7, 2026
Vendor: Red Hat
Source: REDHAT
Vulnerability Report
Generated by CyberWatcher
Description
A flaw was found in ImageMagick. This time-of-check-time-of-use (TOCTOU) vulnerability, involving a symlink race in the video decoder, allows a local attacker with low privileges to bypass path policy write restrictions. By replacing a symbolic link between the security check and the actual file write operation, an attacker can write to locations that should otherwise be protected, potentially leading to unauthorized file modification.
CWE
CWE-367Affected Products
Red Hat Enterprise Linux 6Red Hat Enterprise Linux 7