# Coppermine Photo Gallery Path Traversal Flaw Fixed

Published: 2026-03-11 · Severity: medium
Canonical: https://vorant.io/reports/7b548910-780f-54cd-bfae-e540763da199/coppermine-photo-gallery-path-traversal-flaw-fixed

> An unauthenticated path traversal vulnerability in Coppermine Photo Gallery lets remote attackers read arbitrary files, patched in version 1.6.28.

CERT Polska coordinated disclosure of CVE-2026-3013, a path traversal vulnerability affecting Coppermine Photo Gallery versions 1.6.09 through 1.6.27. The flaw allows an unauthenticated remote attacker to craft payloads against a vulnerable endpoint to read arbitrary files accessible to the web server process, potentially exposing configuration files, credentials, or other sensitive data hosted alongside the application.

The vulnerability was responsibly reported by researcher Jan Paweł Klim and coordinated through CERT Polska's standard disclosure process. The vendor has released version 1.6.28 to remediate the issue. There is no indication in the advisory of active exploitation in the wild; this is a standard vulnerability disclosure and patch notice.

## Mentioned in this report

- Vulnerabilities: CVE-2026-3013

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2026-3013

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/7b548910-780f-54cd-bfae-e540763da199/coppermine-photo-gallery-path-traversal-flaw-fixed.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
