Skip to main content
Vulnerability Database/CVE-2026-42324

CVE-2026-42324: Piwigo Photo Gallery SQL Injection Vulnerability

CVE-2026-42324 is a SQL injection flaw in Piwigo photo gallery that allows authenticated administrators to inject malicious SQL code through image ordering parameters. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-42324 Overview

CVE-2026-42324 is a SQL injection vulnerability in Piwigo, an open source photo gallery application. Versions prior to 16.4.0 fail to enforce the sort-field whitelist in admin/element_set_ranks.php, allowing authenticated administrators to store arbitrary image_order[] values. The stored expression is later concatenated into ORDER BY clauses by admin/batch_manager_global.php, admin/batch_manager_unit.php, include/section_init.inc.php, and include/ws_functions/pwg.categories.php. An attacker can disclose, modify, or disrupt database contents through a stored, second-order SQL injection. The issue is categorized as [CWE-89] and is fixed in Piwigo 16.4.0.

Critical Impact

Authenticated administrators can execute arbitrary SQL against the Piwigo database, leading to data disclosure, modification, or destruction across albums and Batch Manager queries.

Affected Products

  • Piwigo photo gallery application versions prior to 16.4.0
  • admin/element_set_ranks.php (storage sink)
  • admin/batch_manager_global.php, admin/batch_manager_unit.php, include/section_init.inc.php, and include/ws_functions/pwg.categories.php (execution sinks)

Discovery Timeline

  • 2026-09-25 - CVE-2026-42324 published to NVD
  • 2026-09-25 - Last updated in NVD database

Technical Details for CVE-2026-42324

Vulnerability Analysis

Piwigo stores a per-album image_order string that controls the sort order of photos within that album. The administrative endpoint admin/element_set_ranks.php accepts image_order[] values from the request and persists them without validating against the application's existing sort-field whitelist. Because the stored value is later interpolated directly into ORDER BY clauses across multiple consumers, the sink executes attacker-controlled SQL fragments.

This is a stored (second-order) SQL injection. An authenticated administrator writes a crafted expression once, and the payload is triggered by a subsequent album view, API call, or Batch Manager action that references the affected album. The vulnerability requires at least one album containing at least one photo for the ORDER BY clause to execute.

Root Cause

The root cause is missing input validation in admin/element_set_ranks.php. The handler never checked submitted image_order[] entries against the allowed sort-field list before writing them to the database. Downstream code assumed stored values were safe and concatenated them into SQL ORDER BY clauses without parameterization.

Attack Vector

An attacker with administrator credentials submits a crafted POST request to admin/element_set_ranks.php containing a malicious image_order[] value. The payload persists in the album record. On any later query that reads the stored order expression and concatenates it into an ORDER BY clause, the injected SQL executes with the privileges of the Piwigo database user.

php
// Patch in admin/element_set_ranks.php — enforces the allowed sort-field whitelist
include_once(PHPWG_ROOT_PATH.'admin/include/functions.php');

$sort_fields = array(
  ''                    => '',
  'file ASC'            => l10n('File name, A -> Z'),
  'file DESC'           => l10n('File name, Z -> A'),
  'name ASC'            => l10n('Photo title, A -> Z'),
  'name DESC'           => l10n('Photo title, Z -> A'),
  'date_creation DESC'  => l10n('Date created, new -> old'),
  'date_creation ASC'   => l10n('Date created, old -> new'),
  'date_available DESC' => l10n('Date posted, new -> old'),
  'date_available ASC'  => l10n('Date posted, old -> new'),
  'rating_score DESC'   => l10n('Rating score, high -> low'),
  'rating_score ASC'    => l10n('Rating score, low -> high'),
  'hit DESC'            => l10n('Visits, high -> low'),
  'hit ASC'             => l10n('Visits, low -> high'),
  'id ASC'              => l10n('Numeric identifier, 1 -> 9'),
  'id DESC'             => l10n('Numeric identifier, 9 -> 1'),
  'rank ASC'            => l10n('Manual sort order'),
);

Source: Piwigo commit ba1f803f

Detection Methods for CVE-2026-42324

Indicators of Compromise

  • Unexpected values in the Piwigo categories.image_order database column that do not match the official whitelist (file ASC, name DESC, rank ASC, and other documented entries).
  • Database errors or anomalous warnings originating from batch_manager_global.php, batch_manager_unit.php, section_init.inc.php, or the pwg.categories web service endpoint.
  • POST requests to admin/element_set_ranks.php containing non-standard image_order[] parameter values, especially containing SQL keywords such as UNION, SELECT, SLEEP, or BENCHMARK.

Detection Strategies

  • Audit the image_order column in the Piwigo categories table and alert on any value outside the published whitelist.
  • Deploy a Web Application Firewall rule inspecting image_order[] parameters sent to admin/element_set_ranks.php for SQL metacharacters.
  • Review web server access logs for administrator session activity against element_set_ranks.php followed by batch_manager_*.php requests.

Monitoring Recommendations

  • Enable MySQL/MariaDB general query logging on Piwigo backends during incident response to capture executed ORDER BY clauses.
  • Alert on administrator account logins from new IPs or user agents, since exploitation requires privileged credentials.
  • Monitor outbound connections from the web server to detect data exfiltration following successful injection.

How to Mitigate CVE-2026-42324

Immediate Actions Required

  • Upgrade Piwigo to version 16.4.0 or later immediately.
  • Rotate all administrator credentials and review the admin user list for unauthorized accounts.
  • Inspect the categories table for malformed image_order values and reset any entry not matching the official whitelist.

Patch Information

The fix is delivered in Piwigo 16.4.0. The patch adds an explicit $sort_fields whitelist in admin/element_set_ranks.php and rejects any submitted image_order value that does not match an allowed key. Technical details are documented in GitHub Security Advisory GHSA-jhp4-7f82-8f6q with fixes in commits ba1f803f and ef9e6538.

Workarounds

  • Restrict access to admin/element_set_ranks.php at the web server or reverse proxy layer until the patch is applied.
  • Reduce the Piwigo database account privileges to the minimum required, removing rights to sensitive tables and administrative statements.
  • Enforce multi-factor authentication for all Piwigo administrator accounts to reduce the pool of attackers who can reach the vulnerable endpoint.
bash
# Example: upgrade Piwigo to the patched release
cd /var/www/piwigo
php -r "echo PIWIGO_VERSION;" # verify current version
wget https://github.com/Piwigo/Piwigo/releases/download/16.4.0/piwigo-16.4.0.zip
unzip -o piwigo-16.4.0.zip -d /var/www/piwigo-new
rsync -a --exclude=_data --exclude=upload --exclude=galleries /var/www/piwigo-new/piwigo/ /var/www/piwigo/

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.