PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-27833 Piwigo CVE debrief

CVE-2026-27833 is a high-severity vulnerability in Piwigo's pwg.history.search API method, allowing unauthenticated users to access full browsing history. This issue was patched in version 16.3.0. Affected users should prioritize updating to prevent unauthorized access to gallery visitor history. The CVE record was published on 2026-04-03T22:16:25.863Z and has not been modified since then. The NVD entry is currently Analyzed. Evidence is limited to CVE and NVD information. Defenders should verify Piwigo version and update status. Additionally, users should review and restrict access to this API method to prevent potential exploitation.

Vendor
Piwigo
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-03
Original CVE updated
2026-07-24
Advisory published
2026-04-03
Advisory updated
2026-07-24

Who should care

Users of Piwigo photo gallery application, especially those with publicly accessible galleries, should prioritize updating to version 16.3.0 or later to prevent unauthorized access to browsing history. It is also recommended that users review compensating controls for exposed systems while remediation is scheduled and verified.

Technical summary

The pwg.history.search API method in Piwigo was registered without the admin_only option, allowing unauthenticated users to access the full browsing history of all gallery visitors. This issue has been patched in version 16.3.0. Users should review and restrict access to this API method. It is also recommended to monitor for suspicious activity on the Piwigo installation and verify Piwigo version and update status.

Defensive priority

High priority for Piwigo users, especially those with publicly accessible galleries. Users should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Recommended defensive actions

  • Update Piwigo to version 16.3.0 or later
  • Review and restrict access to pwg.history.search API method
  • Monitor for suspicious activity on the Piwigo installation
  • Verify Piwigo version and update status
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record was published on 2026-04-03T22:16:25.863Z and was last modified on 2026-07-24T22:10:00.140Z. The NVD entry is currently Analyzed. Evidence is limited to CVE and NVD information. Defenders should verify Piwigo version and update status. Additionally, defenders should check relevant monitoring, detection, and logs for exposed assets that need extra review.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T22:16:25.863Z and has not been modified since then. The NVD entry is currently Analyzed.