Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-85750— Piwigo arbitrary file read and remote code execution via insecure image processing

Quick assessment

Affected
Piwigo Piwigo
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Piwigo 版本低于 v16.4.0 时,其图像上传处理机制存在任意文件读取和远程代码执行漏洞。该漏洞发生在启用 Imagick 图像处理库的情况下,原因是系统对用户提交的图像文件验证不足且处理不安全。 攻击者可通过利用“格式混淆”技术(例如将 SVG 内容伪装成 PNG 格式),触发对嵌入 SVG 元素的不当解析。这些 SVG 元素可能引用本地文件,从而导致敏感文件被读取。 在更复杂的攻击场景中,攻击者可滥用 Imagick 对 Magick Scripting Language(MSL,Imagick 脚

CVSS 7.2 · High EPSS 1.21% · P67

Affected Version Matrix 1

VendorProduct Version RangeStatus
Piwigo Piwigo <= 16.3.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85750

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Piwigo arbitrary file read and remote code execution via insecure image processing
Source: CVE Program / CVE List V5
Vulnerability Description
Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling when using the Imagick library due to insufficient validation and unsafe processing of user-supplied image files. By abusing format confusion (e.g., disguising SVG content as PNG), an attacker can trigger unintended interpretation of embedded SVG elements that reference local files. In more advanced scenarios, the Imagick support for Magick Scripting Language (MSL) may be abused to process attacker-controlled instructions, potentially leading to unauthorized server-side file writes and remote code execution, depending on configuration. This has been patched in 16.4.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Piwigo Piwigo <= 16.3.0 -

II. Public POCs for CVE-2026-85750

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85750

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-85750 (1)

Security Blog Posts for CVE-2026-85750 (1)

Same Patch Batch · Piwigo · 2026-09-25 · 6 CVEs total

CVE-2026-42322 9.1 CRITICAL Piwigo: Authenticated RCE via File Upload in Logo Upload Feature
CVE-2026-62262 9.1 CRITICAL Piwigo: Unauthenticated SQL injection in `pwg.images.filteredSearch.create`
CVE-2026-44642 8.1 HIGH Piwigo: SQL injection in upgrade authentication allows unauthenticated upgrade authorizati
CVE-2026-42324 7.2 HIGH Piwigo: Second-Order SQL Injection
CVE-2026-42323 7.2 HIGH Piwigo: SQL Injection in Batch Manager

IV. Related Vulnerabilities

V. Comments for CVE-2026-85750

No comments yet


Leave a comment