SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77884

HIGH · CVSS 7.1 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Private Photo Vault app for Android versions up to 1.0.41 is vulnerable due to the initiation of an unauthenticated HTTP server on TCP port 8080, exposing files and directory listings from the device's external storage to anyone on the local network. This could lead to unauthorized access to sensitive personal photos and data. Users of the affected app, particularly those storing private information, should prioritize immediate updates or alternative solutions to mitigate this risk.

CVE
CVE-2026-77884
Severity
HIGH
CVSS
7.1
EPSS
0.32%
Android

Original NVD Description

Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external storage.