Intel

AIKIDO-2026-52179

drupal/photoswipe is vulnerable to Access bypass

Access bypassCVE-2026-16645 Published 4 days ago

44

Medium Risk

This Affects:

PHPdrupal/photoswipe
3.0.0 - 3.0.3
Fixed in 3.0.4
3.1.0 - 3.1.4
Fixed in 3.2.0
Are you affected? Scan for Free

TL;DR

The Photoswipe Drupal module integrates the PhotoSwipe lightbox library for image gallery display formatters. Affected versions do not sufficiently check access permissions when an image is viewed through the photoswipe gallery formatter, which can let unauthorized users view images that should be access-restricted. This is mitigated on sites where photoswipe displays only public images, which is the most common configuration.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and use the photoswipe image gallery formatter to display access-restricted images.

Background info

drupal/photoswipe is vulnerable to Access bypass in versions 3.0.0 - 3.0.3 and 3.1.0 - 3.1.4.

How to fix this

Upgrade the drupal/photoswipe library to the patch version. Use 3.0.4 on Drupal 8 (3.0.x) or 3.2.0 or higher on Drupal 9/10.