PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-44642 Piwigo CVE debrief

CVE-2026-44642 is a high-severity vulnerability in Piwigo, a full-featured open-source photo gallery application for the web. The vulnerability exists in the check_upgrade_access_rights() function in admin/include/functions_upgrade.php, where an unauthenticated username is concatenated directly into the upgrade authentication SQL query on PHP 8 and later. This allows unauthorized database integrity changes and service disruption when database upgrades are pending. The vulnerability is fixed in version 16.4.0.

Vendor
Piwigo
Product
Unknown
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Defenders responsible for Piwigo deployments, particularly those with pending database upgrades, should assess exposure and apply the patch. This vulnerability can lead to unauthorized database changes and service disruption.

Why it matters

CVE-2026-44642 is a high-severity vulnerability in Piwigo that allows unauthorized database changes and service disruption. Defenders should prioritize verifying exposure and applying the patch, particularly in deployments with pending database upgrades.

  • Unauthorized database integrity changes
  • Service disruption due to pending upgrades
  • Potential for crafted query results to bypass authentication
  • Verification of exposure and patch application required

Technical summary

The check_upgrade_access_rights() function in admin/include/functions_upgrade.php conditionally escapes the submitted username only when the removed get_magic_quotes_gpc function exists. On PHP 8 and later, this allows an unauthenticated username to be concatenated directly into the upgrade authentication SQL query. When database upgrades are pending, a crafted query result can satisfy the status and password checks, set PHPWG_IN_UPGRADE, and authorize upgrade execution without valid administrator credentials.

Defensive priority

Defenders should prioritize verifying exposure and applying the patch, as this vulnerability can lead to unauthorized database changes and service disruption.

Recommended defensive actions

  • Verify if Piwigo versions prior to 16.4.0 are in use and apply the patch
  • Review database upgrades and authentication mechanisms for potential exposure
  • Monitor for suspicious database changes and service disruptions
  • Perform an inventory of assets using Piwigo to identify potential exposure
  • Review system logs for signs of unauthorized database changes
  • Implement compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions and retest remediated assets after patch application

Evidence notes

The vulnerability is confirmed to exist in Piwigo versions prior to 16.4.0. The fix is available in version 16.4.0. However, the exact scope of affected deployments and potential impact requires further verification.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-44642 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-44642

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-44642 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44642

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.