Missing Authorization in Piwigo - CVE-2026-27833
Published: April 25, 2026 / Updated: April 26, 2026
Piwigo
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authorization in the pwg.history.search API method when handling requests to the web service endpoint. A remote attacker can send a specially crafted request to disclose sensitive information.
Only instances with web services enabled are vulnerable.