PatchSiren cyber security CVE debrief
CVE-2026-27833 Piwigo CVE debrief
CVE-2026-27833 is a high-severity vulnerability in Piwigo's pwg.history.search API method, allowing unauthenticated users to access full browsing history. This issue was patched in version 16.3.0. Affected users should prioritize updating to prevent unauthorized access to gallery visitor history. The CVE record was published on 2026-04-03T22:16:25.863Z and has not been modified since then. The NVD entry is currently Analyzed. Evidence is limited to CVE and NVD information. Defenders should verify Piwigo version and update status. Additionally, users should review and restrict access to this API method to prevent potential exploitation.
- Vendor
- Piwigo
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-03
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-03
- Advisory updated
- 2026-07-24
Who should care
Users of Piwigo photo gallery application, especially those with publicly accessible galleries, should prioritize updating to version 16.3.0 or later to prevent unauthorized access to browsing history. It is also recommended that users review compensating controls for exposed systems while remediation is scheduled and verified.
Technical summary
The pwg.history.search API method in Piwigo was registered without the admin_only option, allowing unauthenticated users to access the full browsing history of all gallery visitors. This issue has been patched in version 16.3.0. Users should review and restrict access to this API method. It is also recommended to monitor for suspicious activity on the Piwigo installation and verify Piwigo version and update status.
Defensive priority
High priority for Piwigo users, especially those with publicly accessible galleries. Users should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Recommended defensive actions
- Update Piwigo to version 16.3.0 or later
- Review and restrict access to pwg.history.search API method
- Monitor for suspicious activity on the Piwigo installation
- Verify Piwigo version and update status
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions and retest remediated assets
Evidence notes
The CVE record was published on 2026-04-03T22:16:25.863Z and was last modified on 2026-07-24T22:10:00.140Z. The NVD entry is currently Analyzed. Evidence is limited to CVE and NVD information. Defenders should verify Piwigo version and update status. Additionally, defenders should check relevant monitoring, detection, and logs for exposed assets that need extra review.
Official resources
-
CVE-2026-27833 CVE record
CVE.org
-
CVE-2026-27833 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Patch
-
Mitigation or vendor reference
[email protected] - Exploit, Vendor Advisory
-
Mitigation or vendor reference
[email protected] - Release Notes
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T22:16:25.863Z and has not been modified since then. The NVD entry is currently Analyzed.