CVE-2026-84441: Piwigo Image Derivative i.php path traversal
A security vulnerability has been detected in Piwigo up to 16.3.0. Affected by this issue is some unknown functionality of the file i.php of the component Image Derivative Handler. The manipulation leads to path traversal. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Piwigo versions up to and including 16.3.0 are identified as affected. The issue is in the Image Derivative Handler's i.php file.
Can this be exploited remotely without credentials or user interaction?
Yes. The supplied severity vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
What is the likely impact of successful exploitation?
The vulnerability is a path traversal issue and is rated for low confidentiality, integrity, and availability impact. Public exploit disclosure is reported, which may increase the likelihood of attempted exploitation.