EIP-2026-107799

PRE-CVE

Imagick 3.3.0 (PHP 5.4) - disable_functions Bypass

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-107799. PoCs published by RicterZ.

AI-analyzed exploit summary This exploit bypasses PHP's disable_functions by leveraging Imagick's SVG rendering to execute arbitrary commands via a crafted SVG file. The command output is captured in a temporary file and displayed.

Description

Imagick 3.3.0 (PHP 5.4) - disable_functions Bypass

Exploits (1)

exploitdb WORKING POC
by RicterZ · phpwebappsphp
https://www.exploit-db.com/exploits/39766

This exploit bypasses PHP's disable_functions by leveraging Imagick's SVG rendering to execute arbitrary commands via a crafted SVG file. The command output is captured in a temporary file and displayed.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Imagick <= 3.3.0 with PHP >= 5.4
No auth needed
Prerequisites: Imagick extension installed · PHP with disable_functions not blocking file operations
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026