Missing Authentication for Critical Function in ImageMagick - CVE-2026-47165
Published: May 19, 2026
ImageMagick
Detailed vulnerability description
The vulnerability allows a local privileged user to disclose sensitive information.
The vulnerability exists due to improper authentication in distributed pixel cache server when handling distributed pixel cache connections. A local privileged user can access the service without a challenge-response authentication model to disclose sensitive information.