Skip to main content
Vulnerability Database/CVE-2026-44642

CVE-2026-44642: Piwigo Photo Gallery SQL Injection Flaw

CVE-2026-44642 is a SQL injection vulnerability in Piwigo photo gallery that allows unauthenticated attackers to bypass upgrade authentication and execute unauthorized database changes. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-44642 Overview

CVE-2026-44642 is a SQL injection vulnerability in Piwigo, an open-source photo gallery application for the web. The flaw resides in check_upgrade_access_rights() within admin/include/functions_upgrade.php. The function only escapes the submitted username when the deprecated get_magic_quotes_gpc function exists. On PHP 8 and later, that function was removed, so the unauthenticated username is concatenated directly into the upgrade authentication SQL query. Attackers can exploit this during pending database upgrades to bypass administrator authentication and execute upgrade routines. Piwigo fixed the issue in version 16.4.0.

Critical Impact

Unauthenticated attackers can inject SQL into the upgrade authentication query, bypass admin credential checks, set PHPWG_IN_UPGRADE, and trigger unauthorized database modifications or service disruption.

Affected Products

  • Piwigo photo gallery versions prior to 16.4.0
  • Deployments running PHP 8 or later where get_magic_quotes_gpc is absent
  • Instances with pending database upgrades (upgrade workflow reachable)

Discovery Timeline

  • 2026-09-25 - CVE-2026-44642 published to the National Vulnerability Database (NVD)
  • 2026-09-25 - Last updated in NVD database
  • Piwigo 16.4.0 - Patch released via commits 1ff9d045 and 2cfa7a3d

Technical Details for CVE-2026-44642

Vulnerability Analysis

The vulnerability is a classic SQL injection ([CWE-89]) rooted in a legacy PHP compatibility check. In check_upgrade_access_rights(), Piwigo gated input escaping behind function_exists('get_magic_quotes_gpc'). That function was deprecated in PHP 5.4 and removed in PHP 7. On modern PHP runtimes the conditional evaluates to false, so pwg_db_real_escape_string() is never applied to the username parameter.

The unsanitized $_POST['username'] value is then concatenated into the SQL query that validates administrator credentials for upgrade access. A crafted payload can shape the query result so both the account status and password checks are satisfied without valid credentials. Once the check passes, the application defines the PHPWG_IN_UPGRADE constant and permits execution of the upgrade routine. Exploitation requires a pending database upgrade state, which raises attack complexity but does not require authentication.

Root Cause

The root cause is an inverted sanitization condition tied to a removed PHP function. The code only escapes input when a function that no longer exists is present, leaving all PHP 8+ installations vulnerable.

Attack Vector

An unauthenticated remote attacker submits a crafted username value to the upgrade endpoint while the installation has pending upgrades. The injected SQL manipulates the authentication query to return a controlled row, bypassing credential validation and authorizing upgrade execution.

php
// Vulnerable vs. patched check in admin/include/functions_upgrade.php
  $username = $_POST['username'];
  $password = $_POST['password'];

- if(function_exists('get_magic_quotes_gpc') && !@get_magic_quotes_gpc() )
+ if (!function_exists('get_magic_quotes_gpc') or !@get_magic_quotes_gpc())
  {
    $username = pwg_db_real_escape_string($username);
  }

Source: Piwigo Commit 2cfa7a3d

Detection Methods for CVE-2026-44642

Indicators of Compromise

  • POST requests to Piwigo upgrade endpoints (/upgrade.php, /install.php) containing SQL metacharacters such as ', --, UNION, or OR 1=1 in the username field.
  • Unexpected definition of PHPWG_IN_UPGRADE or execution of upgrade scripts without a preceding administrator session.
  • Database schema changes, new admin users, or modified piwigo_users rows that do not correlate with a planned maintenance window.

Detection Strategies

  • Inspect web server access logs for upgrade endpoint access from external IP addresses, especially when the application version is below 16.4.0.
  • Enable database query logging and alert on malformed or union-based queries hitting the Piwigo users table.
  • Deploy WAF rules targeting SQL injection patterns in POST parameters sent to Piwigo administrative paths.

Monitoring Recommendations

  • Alert on repeated failed upgrade authentication attempts followed by a successful one from the same source IP.
  • Monitor filesystem changes to Piwigo PHP files and database upgrade markers for integrity drift.
  • Track outbound connections initiated by the PHP worker during or immediately after upgrade endpoint access.

How to Mitigate CVE-2026-44642

Immediate Actions Required

  • Upgrade all Piwigo instances to version 16.4.0 or later without delay.
  • Restrict network access to /install.php and /upgrade.php so only trusted administrator IP addresses can reach them.
  • Audit Piwigo databases for unauthorized user accounts, modified roles, and unexpected schema changes.

Patch Information

The fix inverts the sanitization condition so that pwg_db_real_escape_string() is applied on PHP 8+ where get_magic_quotes_gpc no longer exists. Review the vendor fix in Piwigo Commit 1ff9d045, Piwigo Commit 2cfa7a3d, and the Piwigo 16.4.0 release. Additional context is available in GitHub Security Advisory GHSA-6wj3-7fhw-gfpm.

Workarounds

  • Block external access to the upgrade and install endpoints at the reverse proxy or web server layer until patching completes.
  • Ensure no pending database upgrade state is left on production instances; complete upgrades promptly in maintenance windows.
  • Place a web application firewall rule in front of Piwigo to reject SQL metacharacters in the username parameter on administrative routes.
bash
# Example nginx snippet to restrict upgrade/install access
location ~ ^/(install|upgrade)\.php$ {
    allow 10.0.0.0/8;        # trusted admin network
    deny  all;
    include fastcgi_params;
    fastcgi_pass unix:/run/php/php8.2-fpm.sock;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.