Arbitrary Command Execution in Piwigo Photo Gallery Application
CVE-2026-42322

9.1CRITICAL

Key Information:

Vendor

Piwigo

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-42322?

Piwigo, an open source photo gallery application, features a vulnerability in its earlier versions where an authenticated administrator can upload malicious files via the logo upload function. By leveraging this vulnerability, an attacker can exploit the system by uploading an image file with a server-executable extension, allowing for potential arbitrary command execution and access to sensitive data. This issue is resolved in version 16.4.0, emphasizing the importance of keeping software updated to mitigate security risks.

Affected Version(s)

Piwigo < 16.4.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.