EIP-2026-107799
PRE-CVEImagick 3.3.0 (PHP 5.4) - disable_functions Bypass
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-107799. PoCs published by RicterZ.
AI-analyzed exploit summary This exploit bypasses PHP's disable_functions by leveraging Imagick's SVG rendering to execute arbitrary commands via a crafted SVG file. The command output is captured in a temporary file and displayed.
Description
Imagick 3.3.0 (PHP 5.4) - disable_functions Bypass
Exploits (1)
exploitdb
WORKING POC
by RicterZ · phpwebappsphp
https://www.exploit-db.com/exploits/39766
This exploit bypasses PHP's disable_functions by leveraging Imagick's SVG rendering to execute arbitrary commands via a crafted SVG file. The command output is captured in a temporary file and displayed.
Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target:
Imagick <= 3.3.0 with PHP >= 5.4
No auth needed
Prerequisites:
Imagick extension installed · PHP with disable_functions not blocking file operations
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026