Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.

Rootio-Imagemagick: Unauthenticated Remote Command Execution

ROOT-OS-DEBIAN-12-CVE-2026-33900
Summary

An issue was found in Rootio's Imagemagick package that could allow an attacker to run unauthorized commands on a server without a password. This affects Root's Debian 12 distribution. To fix this, update to a patched version of the package.

What to do
  • Update rootio-imagemagick to version 8:6.9.11.60+dfsg-1.6+deb12u8.root.io.45.
Affected software
Ecosystem VendorProductAffected versions
Root:Debian:12 – rootio-imagemagick < 8:6.9.11.60+dfsg-1.6+deb12u8.root.io.45
Fix: upgrade to 8:6.9.11.60+dfsg-1.6+deb12u8.root.io.45
Original title
CVE-2026-33900 in rootio-imagemagick - Patched by Root
Original description
Root has patched CVE-2026-33900 in the rootio-imagemagick package for Root:Debian:12. Multiple fixed versions available.
Published: 17 Apr 2026 · Updated: 17 Apr 2026 · First seen: 17 Apr 2026