Junglewise Threat Intelligence

CVE-2026-84441: Piwigo path traversal in image derivative handler

CVE-2026-84441 · Severity: high · CVSS 7.3 · Published 2026-09-02

Technologies: Piwigo. Vendors: Piwigo.

Executive brief

Piwigo is a popular open-source photo gallery software used by photographers and organizations to manage and share image collections. An unauthenticated attacker can exploit a path traversal vulnerability in the image derivative handler (i.php) to write malicious files outside the intended cache directory, potentially enabling arbitrary code execution or defacement of the gallery.

Technical details

The vulnerability is a path traversal flaw in Piwigo's image derivative handler (i.php), which processes and caches resized/transformed image versions. The component fails to properly validate and sanitize file path inputs when constructing derivative image locations, allowing an unauthenticated remote attacker to craft malicious URLs that traverse the directory structure. By manipulating path parameters and using valid derivative suffixes, an attacker can write derivative images to arbitrary locations within the _data directory and potentially beyond, such as theme or plugin directories. No authentication is required, and the attack is network-accessible. Successful exploitation could lead to arbitrary file writes, code injection, or complete compromise of the gallery installation.

Affected products

  • Piwigo Piwigo up to 16.3.0

Timeline

  • 2026-09-02: disclosed
  • other: Proof of concept publicly available on GitHub

References

Related threats