CVE-2026-85750 Overview
Piwigo versions prior to 16.4.0 contain an input validation flaw ([CWE-20]) in the image upload handler when the application uses the Imagick library. Attackers with authenticated access can abuse format confusion to disguise Scalable Vector Graphics (SVG) content as PNG, forcing Imagick to interpret embedded SVG elements that reference local files. Advanced exploitation can leverage Imagick support for the Magick Scripting Language (MSL) to write attacker-controlled files on the server, enabling remote code execution (RCE). The vendor patched the issue in Piwigo 16.4.0.
Critical Impact
Authenticated attackers can read arbitrary files and, in misconfigured environments, achieve remote code execution on the Piwigo host through Imagick MSL abuse.
Affected Products
- Piwigo photo gallery application versions before 16.4.0
- Deployments using the PHP Imagick extension for image processing
- Installations where Imagick policy permits SVG and MSL coders
Discovery Timeline
- 2026-09-25 - CVE CVE-2026-85750 published to the National Vulnerability Database (NVD)
- 2026-09-25 - Last updated in NVD database
Technical Details for CVE-2026-85750
Vulnerability Analysis
The flaw resides in how Piwigo validates and processes user-supplied image files during upload. The application relies on surface-level checks, such as file extension or magic bytes, rather than verifying the actual content structure before passing data to Imagick. Imagick then selects a decoder based on content inspection, so a file named with a PNG extension but containing SVG markup is parsed as SVG. SVG supports external entity references and <image> elements that can point to local filesystem paths, which Imagick dereferences during rasterization. The resulting rendered output exposes file contents to the attacker through the generated thumbnail or preview.
Root Cause
The root cause is insufficient validation of uploaded image data combined with reliance on a permissive image processing backend. Piwigo does not normalize or re-encode uploads before Imagick processing, and it does not enforce a restrictive Imagick policy. When the Imagick policy.xml leaves the SVG and MSL coders enabled, attacker-supplied markup is executed by the ImageMagick delegate chain.
Attack Vector
An authenticated user with upload privileges submits a crafted file through the image upload workflow. The payload embeds SVG directives that reference sensitive files such as /etc/passwd or application configuration files to trigger arbitrary file read. In a more advanced chain, the attacker supplies an MSL script instructing Imagick to write a PHP webshell into a web-accessible directory, which is then executed through a follow-up HTTP request. Exploitation requires high privileges per the CVSS vector but no user interaction.
No verified public proof-of-concept code is available at publication. Refer to the GitHub Security Advisory GHSA-j9q6-q52g-g8jw and the Helx Blog Advisory on Piwigo for additional technical detail.
Detection Methods for CVE-2026-85750
Indicators of Compromise
- Uploaded files in the Piwigo uploads or galleries directories containing SVG or MSL markup despite non-SVG extensions
- Unexpected files written outside the normal upload path, particularly .php or .phtml files in web-accessible directories
- ImageMagick or PHP error logs referencing the MSL, SVG, EPHEMERAL, or URL coders during upload operations
- Outbound network connections from the Piwigo server triggered by SVG <image href="..."> fetches
Detection Strategies
- Inspect image uploads with content-based file type validation and alert when declared MIME type conflicts with detected content
- Monitor the Piwigo application process for child processes spawned by convert, magick, or related ImageMagick binaries
- Alert on web shell indicators appearing in gallery or upload paths through file integrity monitoring
Monitoring Recommendations
- Enable verbose logging for the Piwigo upload endpoint and correlate with authentication logs to identify suspicious upload patterns
- Baseline normal Imagick coder usage and alert on invocation of MSL, MSVG, SVG, or URL coders
- Forward Piwigo and PHP-FPM logs to a centralized SIEM for correlation with filesystem and process telemetry
How to Mitigate CVE-2026-85750
Immediate Actions Required
- Upgrade Piwigo to version 16.4.0 or later on all instances
- Audit the Imagick policy.xml and disable the MSL, MSVG, MVG, SVG, URL, EPHEMERAL, and HTTPS coders unless explicitly required
- Review Piwigo user accounts with upload privileges and remove unnecessary access
- Inspect upload directories for suspicious files written since the earliest possible exploitation window
Patch Information
The Piwigo maintainers released version 16.4.0 to address this vulnerability. Deployment details and advisory metadata are available in the GitHub Security Advisory GHSA-j9q6-q52g-g8jw.
Workarounds
- Harden the ImageMagick policy.xml to deny high-risk coders when upgrading immediately is not feasible
- Place Piwigo behind a web application firewall configured to inspect uploaded file content for SVG and MSL markers
- Restrict upload permissions to a minimal set of trusted administrator accounts until the patch is applied
# Example Imagick policy.xml hardening (append to <policymap>)
<policy domain="coder" rights="none" pattern="MSL" />
<policy domain="coder" rights="none" pattern="MSVG" />
<policy domain="coder" rights="none" pattern="MVG" />
<policy domain="coder" rights="none" pattern="SVG" />
<policy domain="coder" rights="none" pattern="URL" />
<policy domain="coder" rights="none" pattern="HTTPS" />
<policy domain="coder" rights="none" pattern="HTTP" />
<policy domain="coder" rights="none" pattern="EPHEMERAL" />
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.