CVE-2026-42322

Source
https://cve.org/CVERecord?id=CVE-2026-42322
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42322.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-42322
Aliases
  • GHSA-7w97-5g4p-xqvv
Published
2026-09-25T15:50:34Z
Modified
2026-09-29T03:30:41Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Piwigo: Authenticated RCE via File Upload in Logo Upload Feature
Details

Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_standard_pages.php validates uploaded logo content by MIME type but reuses the attacker-controlled extension from std_pgs_logo when constructing the stored filename. An authenticated administrator can upload image content with a server-executable final extension, causing the file to be placed in the web-accessible logo directory and executed when requested if the web server handles that extension. This can permit arbitrary command execution, data disclosure, modification, persistence, and service disruption. This vulnerability is fixed in 16.4.0.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-434"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42322.json"
}
References

Affected packages

Git / github.com/piwigo/piwigo

Affected ranges

Type
GIT
Repo
https://github.com/piwigo/piwigo
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "16.4.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

12.*
12.0.0RC1
12.0.0RC2
12.0.0beta1
12.0.0beta2
13.*
13.0.0RC1
13.0.0RC2
13.0.0RC3
13.0.0RC4
13.0.0beta1
13.0.0beta2
14.*
14.0.0RC1
14.0.0RC2
14.0.0beta1
14.0.0beta2
14.0.0beta3
15.*
15.0.0beta1
15.0.0beta2
15.0.0beta3
16.*
16.0.0
16.0.0RC1
16.0.0RC2
16.0.0RC3
16.0.0beta1
16.0.0beta2
16.1.0
16.2.0
16.3.0
2.*
2.10.0RC1
2.10.0beta1
2.10.0beta2
2.11.0beta1
2.11.0beta2
2.11.0beta3
2.11.0beta4
2.8.0RC1
2.8.0RC2
2.9.0RC1
2.9.0RC2
2.9.0beta1
2.9.0beta2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42322.json"