External risk intelligence

Piwigo Ratings Search SQL Injection Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-62262

Piwigo is a photo gallery application designed specifically to be a public-facing web service. The vulnerability exists within the public search flow and can be triggered by an unauthenticated user, meaning the affected functionality is exposed by design in standard internet-facing deployments.

SQL Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability in Piwigo, an open-source photo gallery application. The issue allows unauthenticated access to extract sensitive database information through the public search function. While a specific fix is not yet available, the potential for data compromise necessitates awareness for organizations using this software.

  • Unauthenticated users can access sensitive data.
  • Critical flaw impacts public-facing photo galleries.
  • Confirm Piwigo usage and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by accessing the Piwigo photo gallery application over the internet. By submitting a specially crafted request to the public search feature, an unauthenticated user can manipulate how search results are processed, potentially leading to the extraction of sensitive information from the database.

  • Guest users can access the feature.
  • Crafted search input triggers the vulnerability.
  • Database information can be disclosed.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated user to extract database information when the rating feature is enabled. This is achieved by manipulating search parameters within the public search functionality, potentially leading to unintended data exposure and service disruption.

  • Database information could be exposed.
  • Exploitation occurs through crafted search URLs.
  • Leads to unauthorized data access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Piwigo's image search functionality requires immediate attention from teams responsible for web applications and their underlying infrastructure. The initial step should be to identify all Piwigo instances, determine their reachability, assess business criticality, and locate the accountable owner to initiate a risk-based remediation plan, especially given the lack of a fixed version.

  • Own the issue: Application owners and infrastructure teams.
  • Verify first: Identify all Piwigo instances.
  • Action follows: Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Piwigo?

Piwigo is an open-source web application used to build and manage photo galleries. It allows users to organize, share, and display image collections online. Because it is designed for public access, it typically handles various user interactions, such as searching and filtering images, directly through web browsers.

What does CVE-2026-62262 mean for security?

This vulnerability is an SQL injection, classified as CWE-89. It happens when the software improperly handles user input in its search function. Instead of treating input as simple text, the application accidentally processes it as database commands. This allows an attacker to manipulate queries to reveal, read, or potentially disrupt information stored in the gallery's underlying database.

How is this vulnerability triggered?

An unauthenticated user can trigger the flaw by sending a specifically crafted request to the image search feature when the rating system is enabled. The bug does not require specialized access or an account to initiate. It is important to note that if the rating feature is disabled, this specific search-based attack path is not applicable.

Why should I care about this if I run Piwigo?

Halo Surface Signal indicates this vulnerability is highly relevant because Piwigo is designed as a public-facing web service. Since the search functionality is exposed by default on the internet, the vulnerability is reachable without internal network access. Organizations running this software on the public web should treat it as a significant risk to their data confidentiality.

What should I do if I use Piwigo?

Since no official patch is available yet, begin by identifying all instances of Piwigo within your environment and confirming their exposure level. Assess the business sensitivity of the data in your galleries to determine your risk profile. While waiting for a fix, consider disabling the rating feature if it is not strictly required for your gallery operations to mitigate this specific entry point.

References