CVE-2026-102777
Received Received - Intake

Server-side Request Forgery in Event Gallery Joomla Extension

Vulnerability report for CVE-2026-102777, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Joomla! Project

Description

Joomla Extension - svenbluege.de - Server-side request forgery in the Google Photos picker in Event Gallery extension < 6.6.0 - The Google Photos picker of the back-end upload page fetches the thumbnails of the picked images through the server, with the OAuth access token of the Google Photos account. The task took the address to fetch from the request without checking it and asked for no form token. A prepared page on another web site could therefore make the server send the access token of the account to any address, or fetch addresses inside the server's network, in the name of a logged in administrator; a back-end user with the permission "Manage" could do the same directly. The token is valid for about an hour and reaches what the picker session of the account reaches.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
svenbluege.de Event Gallery for Joomla 1.0.0-6.6.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a server-side request forgery (SSRF) in the Google Photos picker of the Event Gallery Joomla extension versions before 6.6.0. It allows an attacker to trick the server into fetching thumbnails from arbitrary URLs using the administrator's Google Photos OAuth access token. The token remains valid for about an hour and could be sent to external sites or internal network addresses.

Detection Guidance

To detect this vulnerability, check if the Event Gallery extension version is below 6.6.0. Inspect server logs for unusual outbound requests from the Joomla backend, especially those involving Google Photos OAuth tokens. Monitor network traffic for unauthorized external connections initiated by the server.

Impact Analysis

An attacker could steal the administrator's Google Photos OAuth token, gaining access to their Google Photos account for up to an hour. This could expose sensitive images or allow further attacks within the server's internal network. Back-end users with 'Manage' permissions could also exploit this directly.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data (e.g., images) stored in Google Photos, violating GDPR's data protection principles. For HIPAA, if medical images were involved, it could compromise protected health information (PHI), leading to compliance breaches and legal penalties.

Mitigation Strategies

Immediately update the Event Gallery extension to version 6.6.0 or higher. Disable the Google Photos picker feature in the backend until patched. Review and restrict backend user permissions, especially those with 'Manage' access. Rotate any exposed OAuth tokens and audit recent server activity for signs of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102777. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart