SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16645

CRITICAL · CVSS 9.1 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The PhotoSwipe - Responsive JavaScript Modal Image Gallery in Drupal is vulnerable to a missing authorization flaw, enabling attackers to perform forceful browsing and potentially access restricted content. This vulnerability affects all versions from 0.0.0 to 3.2.0. Organizations using these versions should prioritize remediation to safeguard against unauthorized access to sensitive media.

CVE
CVE-2026-16645
Severity
CRITICAL
CVSS
9.1
EPSS
0.23%
Java

Original NVD Description

Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0.