VYPR
High severity8.1NVD Advisory· Published Sep 25, 2026· Updated Sep 25, 2026

CVE-2026-44642

CVE-2026-44642

Description

Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, check_upgrade_access_rights() in admin/include/functions_upgrade.php conditionally escapes the submitted username only when the removed get_magic_quotes_gpc function exists, so PHP 8 and later concatenate an unauthenticated username directly into the upgrade authentication SQL query. When database upgrades are pending, a crafted query result can satisfy the status and password checks, set PHPWG_IN_UPGRADE, and authorize upgrade execution without valid administrator credentials. This can cause unauthorized database integrity changes and service disruption. This vulnerability is fixed in 16.4.0.

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.