CVE-2026-104079: Envira Gallery Lite < 1.16.2 Missing Authorization via Gallery Conversion REST Endpoint
Envira Gallery Lite before 1.16.2 contains a missing authorization vulnerability in its gallery conversion REST endpoint that allows lower-privileged authenticated users to create and publish Envira galleries without the required capabilities, because the endpoint only checks edit permissions on the source post and uses a hard-coded publish status. Attackers can also supply arbitrary caller-controlled image IDs without ownership verification to publish unauthorized content using attachments they are not authorized to use.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Envira Gallery Liteto a version that resolves this vulnerability.Fixed in 1.16.2
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated lower-privileged user can exploit it if they have edit permission on a source post. No user interaction is required.
What actions can an attacker perform?
They can create and publish Envira galleries without the normally required capabilities. They may also use caller-supplied image IDs without ownership verification, allowing unauthorized attachments to be included in published content.
Which versions are affected?
Envira Gallery Lite versions before 1.16.2 are affected.
What should be done to remediate the issue?
Update Envira Gallery Lite to version 1.16.2 or later. If updating cannot be performed immediately, restrict lower-privileged users' ability to edit source posts that could be converted through the affected REST endpoint.