OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-85750

HIGH · CVSS 7.2 EPSS 1.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Piwigo versions prior to 16.4.0 are vulnerable to arbitrary file read and remote code execution due to inadequate validation of user-uploaded images when using the Imagick library. Attackers can exploit this vulnerability by disguising malicious SVG content as PNG files, leading to unauthorized access and potential server-side file manipulation. Organizations using Piwigo should prioritize patching to version 16.4.0 to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85750
Severity
HIGH
CVSS
7.2
EPSS
1.21%

Original NVD Description

Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling when using the Imagick library due to insufficient validation and unsafe processing of user-supplied image files. By abusing format confusion (e.g., disguising SVG content as PNG), an attacker can trigger unintended interpretation of embedded SVG elements that reference local files. In more advanced scenarios, the Imagick support for Magick Scripting Language (MSL) may be abused to process attacker-controlled instructions, potentially leading to unauthorized server-side file writes and remote code execution, depending on configuration. This has been patched in 16.4.0.