CVE-2026-85750
Last modified
CVE-2026-85750 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling when using the Imagick library due to insufficient validation and unsafe processing of user-supplied image files. By abusing format confusion (e.g., disguising SVG content as PNG), an attacker can trigger unintended interpretation of embedded SVG elements that reference local files.
Description
Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling when using the Imagick library due to insufficient validation and unsafe processing of user-supplied image files. By abusing format confusion (e.g., disguising SVG content as PNG), an attacker can trigger unintended interpretation of embedded SVG elements that reference local files. In more advanced scenarios, the Imagick support for Magick Scripting Language (MSL) may be abused to process attacker-controlled instructions, potentially leading to unauthorized server-side file writes and remote code execution, depending on configuration. This has been patched in 16.4.0.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-85750?
How severe is CVE-2026-85750?
How do I fix CVE-2026-85750?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-85732oras-go is a Go library for managing OCI artifacts. Prior to…4.7
- CVE-2026-85734LightRAG provides simple and fast retrieval-augmented genera…9.1
- CVE-2026-85738TREK is a collaborative travel planner. Prior to 3.4.0, the …6.3
- CVE-2026-8574Use after free in Core in Google Chrome on Windows prior to …8.3
- CVE-2026-85740LightRAG provides simple and fast retrieval-augmented genera…7.1
- CVE-2026-8575Use after free in UI in Google Chrome prior to 148.0.7778.16…8.3
- CVE-2026-85751Mailu is a mail server distributed as a set of Docker images…9.8
- CVE-2026-85756SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2…7.5
- CVE-2026-8576Inappropriate implementation in CORS in Google Chrome on Lin…4.3
- CVE-2026-85769A flaw was found in libtpms, a library that provides softwar…6.5
- CVE-2026-8577Integer overflow in Fonts in Google Chrome prior to 148.0.77…8.8
- CVE-2026-8578Out of bounds read in GPU in Google Chrome on Linux prior to…3.1
Are you affected by CVE-2026-85750?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
