# CVE-2026-27833: Piwigo - Information Disclosure

> Live exploitation tracking for CVE-2026-27833 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-27833

## Key facts

- **Exploitation phase:** Limited Exploitation. The vulnerability is known but shows very limited attacker interest or exploitation activity.
- **CVSS score:** 7.5
- **Public exploit available:** Yes
- **Affected products:** Piwigo
- **Weaknesses:** CWE-862 (Missing Authorization)
- **Tags:** web_application

## Description

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the admin_only option, allowing unauthenticated users to access the full browsing history of all gallery visitors. This issue has been patched in version 16.3.0.

## CrowdSec analysis

[CVE-2026-27833](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-27833) is an information disclosure vulnerability in Piwigo, where the pwg.history.search API method allows unauthenticated users to access the complete browsing history of all gallery visitors. This flaw exposes sensitive user activity data, potentially enabling attackers to track user behavior and compromise privacy. The issue is resolved in Piwigo version 16.3.0.

CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.

According to CrowdSec data, while opportunistic exploitation dominates, a portion of threat actors trying to exploit CVE-2026-27833 apply basic targeting methods such as port or service detection. This indicates emerging patterns of selective targeting.
In addition, according to the CrowdSec network, attack volume against CVE-2026-27833 has dipped slightly compared to the previous week. Although still commonly targeted, the decline suggests a cooling-off period. Long-term relevance remains, but attention is waning.

Attackers exploit unauthenticated requests to the `/ws.php?method=pwg.history.search` endpoint to retrieve sensitive browsing history data from Piwigo installations prior to version 16.3.0.

## Timeline

- 2026-04-03: CVE Published. CVE-2026-27833 is published to NVD.
- 2026-06-24: Rule Released. CrowdSec releases a rule to detect CVE-2026-27833 exploitation attempts against the CrowdSec Network.
- 2026-08-19: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2026-27833 for the first time.

## References

- https://github.com/Piwigo/Piwigo/commit/d05c16561ce3692ca922199f8c8d7b1a45893f1c
- https://github.com/Piwigo/Piwigo/security/advisories/GHSA-397m-gfhm-pmg2
- https://piwigo.org/release-16.3.0
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-27833.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-27833) follows observed exploitation activity for CVE-2026-27833. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
