CRITICAL 9.1 CVE-2026-42322 Published 25 Sept 2026

Piwigo Logo Upload Remote Code Execution Vulnerability

Worried this affects your website?

Piwigo, a full featured open source photo gallery application for the web, is affected by an arbitrary command execution vulnerability prior to version 16.4.0.

The issue is in admin/themes_standard_pages.php: uploaded logo content is validated by MIME type, but the attacker-controlled extension from std_pgs_logo is reused when constructing the stored filename. An authenticated administrator can upload image content with a server-executable final extension, placing the file in the web-accessible logo directory and executing it when requested if the web server handles that extension.

  • Affected versions: prior to 16.4.0
  • Impact: arbitrary command execution, data disclosure, modification, persistence, and service disruption
  • Fixed in: 16.4.0

Reference: CVE-2026-42322 on NVD

← Back to Security News