CVE-2026-28679Disclosure(home-gallery / homegallery)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch home-gallery homegallery systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. Prior to version 1.21.0, when a user requests a download, the application does not verify whether the requested file is located within the media source directory, which can result in sensitive system files being downloadable as well. This issue has been patched in version 1.21.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • homegallery

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-06); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Products
homegallery

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-06: 4Mentions · 2026-03-11: 1Patch / Workaround · 2026-03-06: 2Technical Details · 2026-03-06: 3Technical Details · 2026-03-11: 103-0603-11
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-064
Disclosure3Patch1
2026-03-111
Disclosure1
Full discourse5 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-28679 (CVSS:8.6, HIGH) is Analyzed. http://Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. Prior to version 1.21.0,..https://nvd.nist.gov/vuln/detail/CVE-2026-28679 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post briefly announces CVE-2026‑28679, cites its CVSS score and severity, and links to the NVD entry, but offers no PoC, exploit code, or mitigation information.

    0000015
    172 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-28679 http://Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. Prior to version 1.21.0, when a user requests a download, the applicat… https://www.cve.org/CVERecord?id=CVE-2026-28679 ----- Traducción: CVE-2026-28… http://infoflow.cloud`

    Post summary

    The text announces CVE‑2026‑28679 in Home‑Gallery.org, noting a pre‑1.21.0 download‑related flaw, but provides no PoC, exploit, or patch details.

    0000028
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28679 http://Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. Prior to version 1.21.0, when a user requests a download, the applicat… https://www.cve.org/CVERecord?id=CVE-2026-28679

    Post summary

    CVE-2026-28679 targets Home-Gallery.org before version 1.21.0, affecting the download functionality; the issue is mitigated by updating to v1.21.0. No PoC, exploit, or active threat details are disclosed.

    00000210
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-28679 - High http://Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. Prior to version 1.21.0, when a user requests a download, the application does not verify wheth... https://www.thehackerwire.com/vulnerability/CVE-2026-28679/ https://t.co/mrlWYDXqUx

    Post summary

    The snippet announces CVE‑2026‑28679 as a high‑severity issue in Home‑Gallery.org, highlighting that download requests lack proper verification before v1.21.0, and directs readers to external links for more details.

    0000040
    125 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-28679: HIGH] Critical security update for http://Home-Gallery.org! Version 1.21.0 patches a vulnerability allowing unauthorized downloads of sensitive system files. Update now to stay secure.#cve,CVE-2026-28679,#cybersecurity https://cvefind.com/CVE-2026-28679

    Post summary

    The post announces a critical security update (v1.21.0) that patches CVE-2026-28679, which permitted unauthorized downloads of sensitive system files, and urges users to apply the patch.

    0000055
    597 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphome-galleryhomegallery---

Explore more