CVE-2026-44642 Overview
CVE-2026-44642 is a SQL injection vulnerability in Piwigo, an open-source photo gallery application for the web. The flaw resides in check_upgrade_access_rights() within admin/include/functions_upgrade.php. The function only escapes the submitted username when the deprecated get_magic_quotes_gpc function exists. On PHP 8 and later, that function was removed, so the unauthenticated username is concatenated directly into the upgrade authentication SQL query. Attackers can exploit this during pending database upgrades to bypass administrator authentication and execute upgrade routines. Piwigo fixed the issue in version 16.4.0.
Critical Impact
Unauthenticated attackers can inject SQL into the upgrade authentication query, bypass admin credential checks, set PHPWG_IN_UPGRADE, and trigger unauthorized database modifications or service disruption.
Affected Products
- Piwigo photo gallery versions prior to 16.4.0
- Deployments running PHP 8 or later where get_magic_quotes_gpc is absent
- Instances with pending database upgrades (upgrade workflow reachable)
Discovery Timeline
- 2026-09-25 - CVE-2026-44642 published to the National Vulnerability Database (NVD)
- 2026-09-25 - Last updated in NVD database
- Piwigo 16.4.0 - Patch released via commits 1ff9d045 and 2cfa7a3d
Technical Details for CVE-2026-44642
Vulnerability Analysis
The vulnerability is a classic SQL injection ([CWE-89]) rooted in a legacy PHP compatibility check. In check_upgrade_access_rights(), Piwigo gated input escaping behind function_exists('get_magic_quotes_gpc'). That function was deprecated in PHP 5.4 and removed in PHP 7. On modern PHP runtimes the conditional evaluates to false, so pwg_db_real_escape_string() is never applied to the username parameter.
The unsanitized $_POST['username'] value is then concatenated into the SQL query that validates administrator credentials for upgrade access. A crafted payload can shape the query result so both the account status and password checks are satisfied without valid credentials. Once the check passes, the application defines the PHPWG_IN_UPGRADE constant and permits execution of the upgrade routine. Exploitation requires a pending database upgrade state, which raises attack complexity but does not require authentication.
Root Cause
The root cause is an inverted sanitization condition tied to a removed PHP function. The code only escapes input when a function that no longer exists is present, leaving all PHP 8+ installations vulnerable.
Attack Vector
An unauthenticated remote attacker submits a crafted username value to the upgrade endpoint while the installation has pending upgrades. The injected SQL manipulates the authentication query to return a controlled row, bypassing credential validation and authorizing upgrade execution.
// Vulnerable vs. patched check in admin/include/functions_upgrade.php
$username = $_POST['username'];
$password = $_POST['password'];
- if(function_exists('get_magic_quotes_gpc') && !@get_magic_quotes_gpc() )
+ if (!function_exists('get_magic_quotes_gpc') or !@get_magic_quotes_gpc())
{
$username = pwg_db_real_escape_string($username);
}
Source: Piwigo Commit 2cfa7a3d
Detection Methods for CVE-2026-44642
Indicators of Compromise
- POST requests to Piwigo upgrade endpoints (/upgrade.php, /install.php) containing SQL metacharacters such as ', --, UNION, or OR 1=1 in the username field.
- Unexpected definition of PHPWG_IN_UPGRADE or execution of upgrade scripts without a preceding administrator session.
- Database schema changes, new admin users, or modified piwigo_users rows that do not correlate with a planned maintenance window.
Detection Strategies
- Inspect web server access logs for upgrade endpoint access from external IP addresses, especially when the application version is below 16.4.0.
- Enable database query logging and alert on malformed or union-based queries hitting the Piwigo users table.
- Deploy WAF rules targeting SQL injection patterns in POST parameters sent to Piwigo administrative paths.
Monitoring Recommendations
- Alert on repeated failed upgrade authentication attempts followed by a successful one from the same source IP.
- Monitor filesystem changes to Piwigo PHP files and database upgrade markers for integrity drift.
- Track outbound connections initiated by the PHP worker during or immediately after upgrade endpoint access.
How to Mitigate CVE-2026-44642
Immediate Actions Required
- Upgrade all Piwigo instances to version 16.4.0 or later without delay.
- Restrict network access to /install.php and /upgrade.php so only trusted administrator IP addresses can reach them.
- Audit Piwigo databases for unauthorized user accounts, modified roles, and unexpected schema changes.
Patch Information
The fix inverts the sanitization condition so that pwg_db_real_escape_string() is applied on PHP 8+ where get_magic_quotes_gpc no longer exists. Review the vendor fix in Piwigo Commit 1ff9d045, Piwigo Commit 2cfa7a3d, and the Piwigo 16.4.0 release. Additional context is available in GitHub Security Advisory GHSA-6wj3-7fhw-gfpm.
Workarounds
- Block external access to the upgrade and install endpoints at the reverse proxy or web server layer until patching completes.
- Ensure no pending database upgrade state is left on production instances; complete upgrades promptly in maintenance windows.
- Place a web application firewall rule in front of Piwigo to reject SQL metacharacters in the username parameter on administrative routes.
# Example nginx snippet to restrict upgrade/install access
location ~ ^/(install|upgrade)\.php$ {
allow 10.0.0.0/8; # trusted admin network
deny all;
include fastcgi_params;
fastcgi_pass unix:/run/php/php8.2-fpm.sock;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.