CRITICAL
9.1 CVE-2026-42322 Published 25 Sept 2026
Piwigo Logo Upload Remote Code Execution Vulnerability
Worried this affects your website?
Piwigo, a full featured open source photo gallery application for the web, is affected by an arbitrary command execution vulnerability prior to version 16.4.0.
The issue is in admin/themes_standard_pages.php: uploaded logo content is validated by MIME type, but the attacker-controlled extension from std_pgs_logo is reused when constructing the stored filename. An authenticated administrator can upload image content with a server-executable final extension, placing the file in the web-accessible logo directory and executing it when requested if the web server handles that extension.
- Affected versions: prior to 16.4.0
- Impact: arbitrary command execution, data disclosure, modification, persistence, and service disruption
- Fixed in: 16.4.0
Reference: CVE-2026-42322 on NVD
← Back to Security News