PatchSiren cyber security CVE debrief
CVE-2026-77884 Brain Trust CVE debrief
The CVE-2026-77884 vulnerability in Gallery - Private Photo Vault 1.0.41 allows an unauthenticated HTTP server to be started, reachable from the local network, serving files and directory listings from Android external storage. This issue impacts defenders managing local networks and application security, as it could lead to unauthorized access to sensitive data. The vulnerability has a CVSS score of 7.1 and is considered HIGH severity. The CVE record was published on 2026-09-14T19:17:44.700Z. Further verification is needed to determine affected versions and remediation.
- Vendor
- Brain Trust
- Product
- Gallery - Private Photo Vault
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-14
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-14
- Advisory updated
- 2026-09-18
Who should care
Defenders responsible for managing applications and networks within local environments where Gallery - Private Photo Vault 1.0.41 is used should assess exposure and prioritize mitigation.
Why it matters
CVE-2026-77884 allows unauthenticated access to sensitive data in Gallery - Private Photo Vault 1.0.41, impacting defenders managing local networks and application security.
- Potential unauthorized access to sensitive data stored in Android external storage.
- Possible elevation of privileges within the local network.
- Risk of data breaches or leakage due to unauthenticated access.
Technical summary
The Gallery - Private Photo Vault 1.0.41 application starts an unauthenticated HTTP server on TCP port 8080, serving files and directory listings from Android external storage. This potentially allows unauthorized access to sensitive data. The vulnerability has been assigned a CVSS score of 7.1, indicating HIGH severity. The issue was reported and CVE-2026-77884 was published on 2026-09-14T19:17:44.700Z. Defenders should assess exposure and prioritize mitigation, especially in local network contexts.
Defensive priority
Defenders should prioritize verifying and mitigating exposure to this vulnerability, especially in local network contexts.
Recommended defensive actions
- Verify if the vulnerable version of Gallery - Private Photo Vault is in use within the local network.
- Assess exposure to the unauthenticated HTTP server on TCP port 8080.
- Consider blocking or restricting access to TCP port 8080 from the local network.
- Review and update the application version if a patched version is available.
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability, but further verification is needed to determine affected versions and remediation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-77884 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-77884
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-77884 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77884
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://fluidattacks.com/advisories/suicide
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.