Sceawere

Vulnerability Detail

CVE-2026-94123UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

NextGEN Gallery Unauthenticated File Download

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
Syed Balkhi
Product
NextGEN Gallery
Attack Type
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Arbitrary File Download in NextGEN Gallery <= 4.5.0 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-30T13:17:25.000Z",
  "pubdate": "2026-09-30T13:17:25.000Z",
  "executiveSummary": "The NextGEN Gallery plugin for WordPress, in versions 4.5.0 and below, contains a critical vulnerability involving unauthenticated arbitrary file download.\nThis vulnerability is classified as an improper access control issue, potentially mapped to CWE-200 or CWE-552, where the application fails to adequately restrict access to files on the server.\nThe primary impact of this vulnerability is unauthorized information disclosure. An unauthenticated remote attacker can exploit this flaw to download sensitive system files, configuration files, or sensitive database information from the underlying web server.\nThis vulnerability poses a significant risk as it does not require authentication or specific user privileges, enabling low-complexity exploitation by any remote actor with network access to the target.\nSuccessful exploitation allows attackers to gather actionable intelligence for further system compromise, including the retrieval of credentials or environment-specific configuration data that could lead to full application or server takeover.",
  "technicalDetails": "The root cause of this vulnerability lies in the insecure handling of user-supplied input parameters by the NextGEN Gallery plugin, which fails to perform sufficient path validation or sanitization before passing these inputs to file retrieval functions.\nThe vulnerability resides within the plugin's component responsible for handling file requests, likely where directory traversal sequences are not appropriately neutralized or where the application lacks an allowlist mechanism for accessible file paths.\nThe attack flow begins with an unauthenticated attacker identifying a vulnerable endpoint within the NextGEN Gallery plugin that facilitates file downloads. By crafting a malicious request, the attacker can leverage directory traversal techniques (e.g., using '../' sequences) to navigate outside of the intended directory structure.\nBecause the application does not verify the authenticity or authorization of the request, it proceeds to process the maliciously crafted path. The plugin then retrieves the requested file from the server's filesystem and returns the contents to the attacker's client.\nThis flaw allows for the arbitrary reading of files relative to the web server's service account permissions. If the web server is misconfigured or if critical files (such as wp-config.php or sensitive system logs) are reachable from the web root, the attacker can extract these directly.\nThe vulnerability is present in versions 4.5.0 and earlier. It requires no prior interaction with the application, nor does it require administrative or authenticated access to the WordPress instance. The attack is executable over the network, making it highly accessible to external threat actors.\nPost-exploitation, the attacker gains access to sensitive data contained within the retrieved files. This often includes database credentials, secret keys, or other configuration variables that can be utilized to move laterally within the server environment or facilitate full system compromise via secondary exploitation vectors."
}
CVE-2026-94123: NextGEN Gallery Unauthenticated File Download (HIGH Severity, CVSS: 7.5) | Sceawere