Junglewise Threat Intelligence

CVE-2026-27833: Piwigo missing authorization in pwg.history.search API

CVE-2026-27833 · Severity: high · CVSS 7.5 · Published 2026-04-03

Technologies: Piwigo. Vendors: Piwigo.

Executive brief

Piwigo is an open-source photo gallery application used to manage and display image collections online. A security flaw allows anyone on the internet to access the private browsing history of all gallery visitors without needing a password. This could lead to the exposure of visitor IP addresses, usernames, and details about which specific images were viewed or downloaded.

Technical details

A missing authorization check (CWE-862) exists in the Piwigo web API. The 'pwg.history.search' method in 'ws.php' was registered without the 'admin_only' flag, and the corresponding handler function 'ws_history_search()' in 'include/ws_functions/pwg.php' lacked manual authentication checks. An unauthenticated remote attacker can exploit this by sending a crafted HTTP request to the API to retrieve sensitive information, including visitor IP addresses, user IDs, image viewing/download history, and search queries. The vulnerability is resolved in version 16.3.0 by properly enforcing administrative restrictions on the affected API endpoint.

Affected products

  • Piwigo Piwigo < 16.3.0

Timeline

  • 2026-02-24: patched: Version 16.3.0 released
  • 2026-04-01: advisory: GitHub Security Advisory published
  • 2026-04-03: disclosed: CVE published to NVD

References

Related threats