External risk intelligence

Piwigo Administrator Logo Upload Allows Command Execution

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-42322

Piwigo is a web-based photo gallery application typically deployed as a public-facing website. While this specific vulnerability requires authenticated administrator access, the application itself is designed to be internet-accessible, and the administrative interface is often reachable via the same public web surface.

Unrestricted File Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability has been identified in Piwigo, an open-source photo gallery application. The issue allows an authenticated administrator to potentially execute arbitrary commands on the server, leading to data disclosure, modification, persistence, or service disruption. This impacts the integrity and availability of the photo gallery and potentially other connected systems.

  • Upload flaw allows unauthorized command execution.
  • Affects Piwigo photo gallery application's security.
  • Confirm relevance; critical for authenticated systems.

Attack Path

How an attacker could exploit the issue

An attacker with administrator privileges can upload a specially crafted image file. This file, disguised as a logo, is placed in a web-accessible directory and can be executed by the web server, potentially leading to arbitrary command execution.

  • Authenticated administrator access required.
  • Upload logo with executable extension.
  • Allows arbitrary command execution.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, an authenticated administrator could upload a specially crafted image file that, when accessed, may lead to arbitrary command execution on the web server. This could affect system data, user data, and service behavior.

  • System and user data could be at risk.
  • Malicious files could be uploaded via admin features.
  • Arbitrary command execution and data compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-world ownership of this vulnerability likely resides with the application owner or web infrastructure team managing the Piwigo installation. The first practical step is to identify all instances of Piwigo, confirm their internet reachability and business criticality, and then locate the accountable owner to plan remediation.

  • Application owner(s) should drive remediation.
  • Verify all Piwigo installations.
  • Plan and execute updates during maintenance.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Piwigo?

Piwigo is an open-source web application used to build and manage photo galleries. It allows users to organize digital assets, manage albums, and share photos through a browser-based interface. Because it is designed to be hosted on web servers, it handles file uploads and media processing to support its core gallery functionality.

What is the vulnerability in CVE-2026-42322?

This issue is an Unrestricted Upload of File with Dangerous Type, classified as CWE-434. It occurs because the application improperly validates the file extension of uploaded logos. By bypassing these checks, a user can upload a file that the web server treats as executable code rather than a simple image, potentially allowing the execution of arbitrary commands on the underlying server.

How does an attacker trigger this vulnerability?

The flaw requires an attacker to already possess authenticated administrator access to the Piwigo dashboard. They must specifically upload a malicious file through the logo configuration feature. Simply visiting the site or uploading standard photos as a regular user does not trigger this vulnerability, as it relies on the specific administrative function that fails to secure the file naming process.

Is my Piwigo instance at risk?

According to Halo Surface Signal, Piwigo is typically deployed as a public-facing website, which increases the likelihood of exposure. Since the administrative interface is often reachable via the same internet-accessible path, any instance running a version prior to 16.4.0 should be treated as potentially reachable. You should evaluate if your installation is accessible from the internet and who maintains administrative credentials.

What should I do if I run Piwigo?

The primary response is to update your Piwigo installation to version 16.4.0 or later, which contains the fix for this flaw. Start by auditing your environment to locate all active Piwigo instances. Once identified, coordinate with your infrastructure or application team to schedule the update during your next maintenance window to ensure service stability.

References