| CVE ID | CVE-2026-3013 |
| Publication date | 11 March 2026 |
| Vendor | Coppermine Photo Gallery |
| Product | Coppermine Photo Gallery |
| Vulnerable versions | From 1.6.09 to 1.6.27 |
| Vulnerability type (CWE) | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Coppermine Photo Gallery software and participated in coordination of its disclosure.
The vulnerability CVE-2026-3013: Coppermine Photo Gallery in versions 1.6.09 through 1.6.27 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit vulnerable endpoint and construct payloads that allow to read content of any file accessible by the the web server process. This issue was fixed in version 1.6.28.
Credits
We thank Jan Paweł Klim for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.