Junglewise Threat Intelligence

CVE-2026-16645: Drupal PhotoSwipe authorization bypass in image gallery display

CVE-2026-16645 · Severity: critical · CVSS 9.1 · Published 2026-08-25

Vendors: Drupal, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

The PhotoSwipe Drupal module is a popular image gallery and lightbox display plugin used on thousands of Drupal websites. The module failed to properly check access permissions when displaying images through its gallery formatter, potentially allowing unauthorized users to view images that should have been restricted. This affects primarily sites that rely on access controls to limit who can view specific images.

Technical details

This is an authorization bypass vulnerability in the PhotoSwipe module's image formatter implementation. The vulnerable component failed to sufficiently validate access permissions before displaying images through the photoswipe gallery display formatter in versions before 3.0.4 (Drupal 8) and 3.2.0 (Drupal 9/10). The vulnerability allows an authenticated or unauthenticated attacker to forcefully browse and access images that should be protected by site access control rules. The impact is mitigated on sites using photoswipe for public image galleries, but is critical for sites restricting image visibility. Patches are available in versions 3.0.4, 3.1.x (deprecated), and 3.2.0 or higher.

Affected products

  • Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery before 3.0.4 (Drupal 8); before 3.2.0 (Drupal 9/10)

Timeline

  • 2026-07-22: disclosed
  • 2026-08-25: advisory

References

Related threats