Coppermine Photo Gallery Path Traversal Flaw Fixed
An unauthenticated path traversal vulnerability in Coppermine Photo Gallery lets remote attackers read arbitrary files, patched in version 1.6.28.
CERT Polska coordinated disclosure of CVE-2026-3013, a path traversal vulnerability affecting Coppermine Photo Gallery versions 1.6.09 through 1.6.27. The flaw allows an unauthenticated remote attacker to craft payloads against a vulnerable endpoint to read arbitrary files accessible to the web server process, potentially exposing configuration files, credentials, or other sensitive data hosted alongside the application.
The vulnerability was responsibly reported by researcher Jan Paweł Klim and coordinated through CERT Polska's standard disclosure process. The vendor has released version 1.6.28 to remediate the issue. There is no indication in the advisory of active exploitation in the wild; this is a standard vulnerability disclosure and patch notice.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/03/CVE-2026-3013
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free