Description
Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external storage.
Published: 2026-09-14
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external storage.
Title Gallery - Private Photo Vault 1.0.41 - Unauthenticated local-network HTTP file exposure
First Time appeared Brain Trust
Brain Trust gallery - Private Photo Vault
Weaknesses CWE-552
CPEs cpe:2.3:a:brain_trust:gallery_-_private_photo_vault:1.0.41:*:android:*:*:*:*:*
Vendors & Products Brain Trust
Brain Trust gallery - Private Photo Vault
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Brain Trust Gallery - Private Photo Vault
cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published:

Updated: 2026-09-14T19:04:22.864Z

Reserved: 2026-08-21T16:42:06.909Z

Link: CVE-2026-77884

cve-icon Vulnrichment

Updated: 2026-09-14T19:04:17.085Z

cve-icon NVD

Status : Received

Published: 2026-09-14T19:17:44.700

Modified: 2026-09-14T19:17:44.700

Link: CVE-2026-77884

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses