Skip to main content
Vulnerability Database/CVE-2026-42323

CVE-2026-42323: Piwigo Batch Manager SQL Injection Vulnerability

CVE-2026-42323 is a SQL injection flaw in Piwigo photo gallery that allows authenticated administrators to execute malicious SQL queries. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-42323 Overview

Piwigo is an open source photo gallery application written in PHP. CVE-2026-42323 is a SQL injection vulnerability [CWE-89] in admin/batch_manager.php affecting versions prior to 16.4.0. The Batch Manager filter URL parser accepts administrator-controlled width, height, ratio, and filesize values without numeric validation. These values are stored in the bulk_manager_filter session state and later concatenated into SQL predicates. An authenticated administrator can craft filter values to execute time-based or arbitrary SQL expressions. The flaw is fixed in Piwigo 16.4.0.

Critical Impact

An authenticated administrator can inject SQL through Batch Manager filter URL parameters to disclose, modify, or disrupt database contents.

Affected Products

  • Piwigo photo gallery application versions prior to 16.4.0
  • Deployments exposing admin/batch_manager.php to administrator sessions
  • Instances relying on the GET filter path rather than the validated POST filter path

Discovery Timeline

  • 2026-09-25 - CVE-2026-42323 published to NVD
  • 2026-09-28 - Last updated in NVD database

Technical Details for CVE-2026-42323

Vulnerability Analysis

The vulnerability resides in the Batch Manager URL filter parser inside admin/batch_manager.php. When Piwigo processes a filter string such as filter=dimension-w10..1000-h100..5000-r0.70..2, the parser splits the segments and assigns the raw values directly into $_SESSION['bulk_manager_filter']['dimension']['min_<type>'] and max_<type> entries. The same unchecked flow applies to filesize bounds. Downstream query construction concatenates these session values into SQL predicates to filter media by dimensions and size. Unlike the POST-based filter submission, which validates input, the GET parser performs no type checking before persisting the values. An authenticated administrator can therefore embed SQL fragments inside dimension or filesize URL parameters and have them injected into subsequent SELECT predicates. The attack requires administrator privileges, limiting unauthenticated exploitation but still enabling horizontal data access across the database, privilege persistence, or destructive operations against the Piwigo schema.

Root Cause

The root cause is missing input validation on URL-sourced filter values. The parser trusts positional segments from the GET string and writes them into session state without applying FILTER_VALIDATE_INT or FILTER_VALIDATE_FLOAT. Later query builders assume numeric content and concatenate the values into SQL fragments, converting a parsing oversight into a classic SQL injection sink.

Attack Vector

Exploitation requires an authenticated administrator session. The attacker sends a crafted request to the Batch Manager endpoint with malicious dimension or filesize fragments in the filter URL parameter. Once stored in the session, the payload executes on subsequent Batch Manager queries, enabling time-based inference, data extraction, modification, or denial of service against the backing database.

php
       break;
 
     case 'dimension':
+      // filter=dimension-w10..1000-h100..5000-r0.70..2
       $dim_map = array('w'=>'width','h'=>'height','r'=>'ratio');
       foreach (explode('-', $value) as $part)
       {
         $values = explode('..', substr($part, 1));
         if (isset($dim_map[$part[0]]))
         {
           $type = $dim_map[$part[0]];
-          list(
-            $_SESSION['bulk_manager_filter']['dimension']['min_'.$type],
-            $_SESSION['bulk_manager_filter']['dimension']['max_'.$type]
-          ) = $values;
+
+          $filter_to_validate_for_type = array(
+            'width' => FILTER_VALIDATE_INT,
+            'height' => FILTER_VALIDATE_INT,
+            'ratio' => FILTER_VALIDATE_FLOAT,
+          );
+
+          $valid = true;
+          foreach ($values as $value)
+          {
+            if (filter_var($value, $filter_to_validate_for_type[$type]) === false)
+            {
+              $valid = false;
+            }
+          }

Source: Piwigo Commit c7e30da. The patch introduces filter_var validation against FILTER_VALIDATE_INT and FILTER_VALIDATE_FLOAT before any value is written into the session.

Detection Methods for CVE-2026-42323

Indicators of Compromise

  • Web server access logs containing requests to admin/batch_manager.php with filter=dimension- or filter=filesize- parameters that include SQL metacharacters such as single quotes, parentheses, SLEEP(, BENCHMARK(, or UNION.
  • Unexpected delays on Batch Manager page loads consistent with time-based SQL injection payloads.
  • Database error entries or slow query log activity originating from Piwigo Batch Manager queries filtering on width, height, ratio, or filesize columns.

Detection Strategies

  • Alert on administrator GET requests to admin/batch_manager.php whose filter query string contains non-numeric characters inside w, h, r, or filesize ranges.
  • Deploy a web application firewall rule that enforces numeric and float patterns against dimension and filesize segments of the Piwigo filter URL grammar.
  • Correlate administrator logins with subsequent anomalous SQL activity against the Piwigo database to surface post-authentication abuse.

Monitoring Recommendations

  • Enable verbose logging of administrative endpoints and ship Piwigo access logs to a centralized analytics platform for anomaly review.
  • Monitor the MySQL general or slow query log for Batch Manager queries that reference string literals in numeric predicate positions.
  • Review administrator account activity for session reuse from unexpected IP ranges, since the flaw requires an authenticated admin context.

How to Mitigate CVE-2026-42323

Immediate Actions Required

  • Upgrade all Piwigo instances to version 16.4.0 or later, which enforces FILTER_VALIDATE_INT and FILTER_VALIDATE_FLOAT on filter values.
  • Audit administrator accounts, rotate credentials, and enforce multi-factor authentication for all users with Batch Manager access.
  • Review the Piwigo database for unauthorized modifications, unexpected tables, or injected content since the vulnerable version was deployed.

Patch Information

The fix is delivered in Piwigo Release 16.4.0. The relevant commits are Piwigo Commit c7e30da and Piwigo Commit e4f0989. Technical context is documented in GitHub Security Advisory GHSA-7r67-9xhq-7p2c.

Workarounds

  • Restrict access to admin/batch_manager.php using web server rules that only allow trusted administrator source IP addresses until the patch is applied.
  • Deploy a WAF signature that rejects non-numeric content inside Piwigo Batch Manager filter URL parameters.
  • Temporarily disable Batch Manager usage and manage media through the validated POST-based workflows, which are not affected by this parser flaw.
bash
# Upgrade Piwigo to the patched release
cd /var/www/piwigo
php -r "echo PIWIGO_VERSION;" || true
# Backup first
tar czf piwigo-backup-$(date +%F).tar.gz .
# Fetch 16.4.0
curl -L -o piwigo-16.4.0.zip https://github.com/Piwigo/Piwigo/releases/download/16.4.0/piwigo-16.4.0.zip
unzip -o piwigo-16.4.0.zip

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.