CVE-2026-77884
Last modified
CVE-2026-77884 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external storage.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external storage.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Brain Trust | Gallery - Private Photo Vault | 1.0.41 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-77884?
How severe is CVE-2026-77884?
How do I fix CVE-2026-77884?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-77860In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vu…3.7
- CVE-2026-77866Server-Side Request Forgery (SSRF) vulnerability in Slab saf…9
- CVE-2026-7787IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenti…8.1
- CVE-2026-77875The application protects access through its calculator-style…6.8
- CVE-2026-7788A security flaw has been discovered in Axle-Bucamp MCP-Docus…7.3
- CVE-2026-77883Exposure of sensitive information through data queries vulne…4.9
- CVE-2026-77886Out-of-bounds read in Windows DHCP Server allows an unauthor…7.5
- CVE-2026-77887Out-of-bounds read in Windows DHCP Server allows an authoriz…6.4
- CVE-2026-77888Access of resource using incompatible type ('type confusion'…7.5
- CVE-2026-77889Access of resource using incompatible type ('type confusion'…7.5
- CVE-2026-77890Access of resource using incompatible type ('type confusion'…7.5
- CVE-2026-77891Out-of-bounds read in Windows DHCP Server allows an authoriz…6.4
Are you affected by CVE-2026-77884?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
