


Perceptive Security
SOC/SIEM Consultancy

A security vulnerability has been detected in Piwigo up to 16.3.0. Affected by this issue is some unknown functionality of the file i.php of the component Image…
Published:
2 September 2026 at 00:00:00
Alert date:
2 September 2026 at 06:01:21
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
A path traversal vulnerability has been identified in Piwigo versions up to 16.3.0, affecting the i.php file within the Image Derivative Handler component. The flaw allows remote attackers to traverse file system paths without authentication. The vulnerability has been publicly disclosed with a proof-of-concept exploit available on GitHub, increasing the risk of active exploitation. Remote exploitation is possible without requiring local access or elevated privileges. The issue stems from improper input validation in the image derivative handling functionality. Organizations using Piwigo up to version 16.3.0 are advised to review and apply any available patches or mitigations. The public availability of the exploit raises the severity and urgency of remediation.
Technical details
Mitigation steps:
Affected products:
Piwigo up to 16.3.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-84441
https://github.com/Leousum/VulnPoC/blob/main/Piwigo%2016.3.0/unauthenticated_derivative_path_traversal.md
https://vuldb.com/cve/CVE-2026-84441
https://vuldb.com/submit/885229
https://vuldb.com/vuln/397806
https://vuldb.com/vuln/397806/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
