Skip to main content
Vulnerability Database/CVE-2026-42322

CVE-2026-42322: Piwigo Photo Gallery RCE Vulnerability

CVE-2026-42322 is a remote code execution vulnerability in Piwigo photo gallery that lets authenticated admins upload malicious files with executable extensions, enabling arbitrary command execution. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-42322 Overview

Piwigo is a full-featured open source photo gallery application. Versions prior to 16.4.0 contain an unrestricted file upload vulnerability in admin/themes_standard_pages.php. The code validates uploaded logo content by Multipurpose Internet Mail Extensions (MIME) type but reuses the attacker-controlled extension from std_pgs_logo when constructing the stored filename. An authenticated administrator can upload image content with a server-executable final extension. The file lands in the web-accessible logo directory and executes when requested, provided the web server handles that extension. This flaw is tracked as [CWE-434] Unrestricted Upload of File with Dangerous Type and is fixed in release 16.4.0.

Critical Impact

Successful exploitation grants arbitrary command execution on the Piwigo host, enabling data disclosure, data modification, persistence, and service disruption.

Affected Products

  • Piwigo photo gallery versions prior to 16.4.0
  • Deployments where the web server executes scripts in the logo upload directory
  • Instances exposing administrator or webmaster accounts to untrusted actors

Discovery Timeline

  • 2026-09-25 - CVE-2026-42322 published to the National Vulnerability Database (NVD)
  • 2026-09-28 - Last updated in NVD database

Technical Details for CVE-2026-42322

Vulnerability Analysis

The flaw lives in Piwigo's standard pages administration handler, admin/themes_standard_pages.php. During a logo upload, the handler inspects the file's MIME type to confirm it is an image. However, the stored filename is built from the attacker-controlled std_pgs_logo parameter, including its extension. An attacker can submit a payload whose byte content passes MIME detection as an image while its filename ends in .php or another server-executable extension. The file is then written to the web-accessible logo directory and interpreted by the web server on request.

Root Cause

The root cause is a mismatch between content validation and filename construction. MIME sniffing confirms the body is an image, but the extension is never normalized or whitelisted against a safe set. Any attacker-provided suffix is trusted, violating [CWE-434] by allowing files of dangerous type to reach an executable path. The pre-patch handler also lacked a webmaster role check, meaning any administrator could reach the vulnerable code path.

Attack Vector

Exploitation requires authenticated access with administrator privileges. The attacker uploads a polyglot or crafted image file whose filename carries an executable extension such as .php through the standard pages logo configuration. A follow-up HTTP request to the stored logo path triggers interpretation by the web server, yielding command execution in the context of the web process.

php
// Patch excerpt from admin/themes_standard_pages.php
// Source: https://github.com/Piwigo/Piwigo/commit/4a13ec9a8f4881ae1f23bdfd24d7b90cd0802cdc
 check_status(ACCESS_ADMINISTRATOR);

+if (!is_webmaster())
+{
+  $page['warnings'][] = str_replace('%s', l10n('user_status_webmaster'), l10n('%s status is required to edit parameters.'));
+}
+
 // +-----------------------------------------------------------------------+
 // | Update standard pages configuration                                   |
 // +-----------------------------------------------------------------------+

The patch adds a is_webmaster() enforcement check, reducing the attack surface. The companion commit 1e7f726 backports the same hardening.

Detection Methods for CVE-2026-42322

Indicators of Compromise

  • Files with executable extensions such as .php, .phtml, or .phar present in Piwigo's logo upload directory under the active theme or standard pages path
  • Unexpected POST requests to admin.php?page=themes&tab=standard_pages containing std_pgs_logo values ending in non-image extensions
  • Outbound connections from the Piwigo web server process to attacker-controlled infrastructure following a logo upload
  • New administrator accounts, modified configuration files, or scheduled tasks created shortly after suspicious logo uploads

Detection Strategies

  • Audit the web root for files whose extension does not match an allowlist of image types (.png, .jpg, .jpeg, .gif, .webp, .svg)
  • Inspect web server access logs for GET requests directly against files inside the logo directory with script extensions
  • Review Piwigo administrator activity logs for logo configuration changes correlated with new files on disk

Monitoring Recommendations

  • Enable file integrity monitoring on Piwigo's theme and logo directories to alert on any new executable file
  • Forward web server and PHP-FPM logs to a centralized analytics platform for anomaly detection on administrator endpoints
  • Alert on web server processes spawning shells (sh, bash, cmd.exe) or network utilities such as curl and wget

How to Mitigate CVE-2026-42322

Immediate Actions Required

  • Upgrade Piwigo to version 16.4.0 or later, which contains the fix from commits 4a13ec9 and 1e7f726
  • Rotate credentials for all administrator and webmaster accounts following the upgrade
  • Hunt for web shells or unexpected scripts in the logo and theme directories before returning the application to production

Patch Information

The vulnerability is fixed in the Piwigo 16.4.0 release. Full technical context is available in GitHub Security Advisory GHSA-7w97-5g4p-xqvv.

Workarounds

  • Restrict access to admin/themes_standard_pages.php through web server rules until the upgrade is applied
  • Configure the web server to deny script execution within the logo and uploads directories using location-based handler overrides
  • Limit administrator and webmaster roles to a minimal set of trusted operators and enforce multi-factor authentication on those accounts
bash
# Example Apache configuration to disable PHP execution in Piwigo upload paths
<Directory "/var/www/piwigo/_data/i">
    php_admin_flag engine off
    <FilesMatch "\.(php|phtml|phar)$">
        Require all denied
    </FilesMatch>
</Directory>

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.