{"id":"CVE-2026-44642","summary":"Piwigo: SQL injection in upgrade authentication allows unauthenticated upgrade authorization bypass (PHP 8+)","details":"Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, check_upgrade_access_rights() in admin/include/functions_upgrade.php conditionally escapes the submitted username only when the removed get_magic_quotes_gpc function exists, so PHP 8 and later concatenate an unauthenticated username directly into the upgrade authentication SQL query. When database upgrades are pending, a crafted query result can satisfy the status and password checks, set PHPWG_IN_UPGRADE, and authorize upgrade execution without valid administrator credentials. This can cause unauthorized database integrity changes and service disruption. This vulnerability is fixed in 16.4.0.","aliases":["GHSA-6wj3-7fhw-gfpm"],"modified":"2026-09-27T03:47:28.076560778Z","published":"2026-09-25T15:47:59.389Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-89"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44642.json"},"references":[{"type":"WEB","url":"https://github.com/Piwigo/Piwigo/releases/tag/16.4.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44642.json"},{"type":"ADVISORY","url":"https://github.com/Piwigo/Piwigo/security/advisories/GHSA-6wj3-7fhw-gfpm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44642"},{"type":"FIX","url":"https://github.com/Piwigo/Piwigo/commit/1ff9d04534feb5f8f3cc2d3613c0fe8b51a1c0ba"},{"type":"FIX","url":"https://github.com/Piwigo/Piwigo/commit/2cfa7a3d194c8b95edde43038d8f5be5a359e785"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/piwigo/piwigo","events":[{"introduced":"0"},{"fixed":"1ff9d04534feb5f8f3cc2d3613c0fe8b51a1c0ba"},{"fixed":"2cfa7a3d194c8b95edde43038d8f5be5a359e785"},{"fixed":"bef1a4ac424b4e986589e4cfc9f4d134f1b16f15"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"16.4.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["16.3.0","16.2.0","16.1.0","16.0.0","16.0.0RC3","16.0.0RC2","16.0.0RC1","16.0.0beta2","16.0.0beta1","15.0.0beta3","15.0.0beta2","15.0.0beta1","14.0.0RC2","14.0.0RC1","14.0.0beta3","14.0.0beta2","14.0.0beta1","13.0.0RC4","13.0.0RC3","13.0.0RC2","13.0.0RC1","13.0.0beta2","13.0.0beta1","12.0.0RC2","12.0.0RC1","12.0.0beta2","12.0.0beta1","2.11.0beta4","2.11.0beta3","2.11.0beta2","2.11.0beta1","2.10.0RC1","2.10.0beta2","2.10.0beta1","2.9.0RC2","2.9.0RC1","2.9.0beta2","2.9.0beta1","2.8.0RC2","2.8.0RC1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44642.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}