PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-27833 Piwigo CVE debrief

CVE-2026-27833 is a high-severity vulnerability in Piwigo's pwg.history.search API method, allowing unauthenticated users to access full browsing history. This issue was patched in version 16.3.0. Affected users should prioritize updating to prevent unauthorized access to gallery visitor history. The CVE record was published on 2026-04-03T22:16:25.863Z and has not been modified since then. The NVD entry is currently Analyzed. Evidence is limited to CVE and NVD information. Defenders should verify Piwigo version and update status. Additionally, users should review and restrict access to this API method to prevent potential exploitation.

Vendor
Piwigo
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-03
Original CVE updated
2026-07-24
Advisory published
2026-04-03
Advisory updated
2026-07-24

Who should care

Users of Piwigo photo gallery application, especially those with publicly accessible galleries, should prioritize updating to version 16.3.0 or later to prevent unauthorized access to browsing history. It is also recommended that users review compensating controls for exposed systems while remediation is scheduled and verified.

Technical summary

The pwg.history.search API method in Piwigo was registered without the admin_only option, allowing unauthenticated users to access the full browsing history of all gallery visitors. This issue has been patched in version 16.3.0. Users should review and restrict access to this API method. It is also recommended to monitor for suspicious activity on the Piwigo installation and verify Piwigo version and update status.

Defensive priority

High priority for Piwigo users, especially those with publicly accessible galleries. Users should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Recommended defensive actions

  • Update Piwigo to version 16.3.0 or later
  • Review and restrict access to pwg.history.search API method
  • Monitor for suspicious activity on the Piwigo installation
  • Verify Piwigo version and update status
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record was published on 2026-04-03T22:16:25.863Z and was last modified on 2026-07-24T22:10:00.140Z. The NVD entry is currently Analyzed. Evidence is limited to CVE and NVD information. Defenders should verify Piwigo version and update status. Additionally, defenders should check relevant monitoring, detection, and logs for exposed assets that need extra review.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-27833 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-27833

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-27833 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-27833

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.