Arbitrary File Read and Remote Code Execution Vulnerability in Piwigo by Piwigo
CVE-2026-85750

7.2HIGH

Key Information:

Vendor

Piwigo

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-85750?

Piwigo, prior to version 16.4.0, is susceptible to a significant vulnerability that enables arbitrary file reading and may lead to remote code execution during image upload handling. This arises from inadequate validation and insecure processing of user-uploaded image files, particularly when utilizing the Imagick library. Attackers can exploit format confusion—posing SVG content as PNGs—to trigger misinterpretation of malicious embedded SVG components referencing local files. Furthermore, the Imagick library's support for Magick Scripting Language (MSL) can be leveraged to process harmful commands, potentially allowing unauthorized file manipulations and code execution on the server, contingent on the system's configuration. This vulnerability has been addressed in Piwigo version 16.4.0.

Affected Version(s)

Piwigo <= 16.3.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.