Summary
CVE-2026-35048 is a critical unauthenticated remote code execution (RCE) vulnerability in the Piwigo open-source photo gallery application, affecting all versions up to and including 16.3.0. The flaw resides in Piwigo’s installer endpoint (install.php), where attacker-controlled POST parameters are written directly into a PHP configuration file without adequate sanitization — a protection gap triggered by a PHP 8.0 compatibility regression. Piwigo has addressed the issue in version 16.4.0 and the vulnerability carries a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause: The installer (
install.php) accepts database configuration POST parameters —prefix,dbpasswd,dbhost,dbname, anddbuser— and writes their values directly intolocal/config/database.inc.php. The existingaddslashes()sanitization is silently rendered ineffective on PHP 8+ because it conditionally checks forget_magic_quotes_gpc(), a function that was permanently removed in PHP 8.0. With the check returning false, raw user input is interpolated directly into PHP source code in the config file. - Trigger conditions: The installer endpoint (
install.php) must be network-accessible. This condition exists on newly deployed instances and on misconfigured production deployments where the installer has not been removed or restricted after initial setup. - Attack vector: An unauthenticated remote attacker submits a crafted HTTP POST request to
install.phpcontaining arbitrary PHP code embedded within one or more of the database configuration parameters. No credentials, prior access, or user interaction are required. - Impact: The injected PHP payload is persisted to
local/config/database.inc.phpand executed on every subsequent page load, resulting in persistent, server-side remote code execution. Full confidentiality, integrity, and availability compromise is possible.
Affected software
- Piwigo 16.3.0 and all earlier versions
Severity
CVSS v3.1 base score: 9.8 (Critical)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Patch: Upgrade to Piwigo 16.4.0, which introduces input sanity checks for installer parameters, directly addressing this vulnerability (GHSA-gphq-34pv-gvf3).
- Workaround (if immediate upgrade is not possible): Remove or restrict network access to
install.phpon all production Piwigo instances. The installer serves no function after initial setup and should never be internet-accessible on a live deployment.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

