ZeroHour

CVE-2026-77884

Unauthenticated HTTP File Server Exposes Android Storage in Gallery Private Photo Vault

CVSS 4.0
7.1 high
EPSS
Published
()
Modified
AI analysis

Gallery – Private Photo Vault 1.0.41 for Android starts an unauthenticated HTTP server that listens on TCP port 8080 and is reachable from the local network, classified as CWE-552 (files or directories accessible to external parties). Any attacker on the same Wi-Fi or LAN segment can connect with no credentials and browse directory listings and download files from Android external storage. This defeats the app's core purpose of protecting private media, exposing stored photos and any other files in those directories to read access; the flaw is rated CVSS:4.0 7.1 (high) with an adjacent-network attack vector and high confidentiality impact. Users running version 1.0.41 are affected whenever the app's server is active and the device is on a shared network such as public or home Wi-Fi. No public proof of concept is known, there is no evidence of in-the-wild exploitation, and the CVE is not in CISA's KEV catalog.

What to do: Upgrade Gallery – Private Photo Vault past version 1.0.41 as soon as the vendor releases a fixed build, since 1.0.41 is the confirmed affected version. In the interim, avoid running the app on shared or untrusted Wi-Fi, enable AP/client isolation on routers you control, or uninstall the app and revoke its storage permissions. From another device on the same network, check whether the phone responds on TCP port 8080 to confirm whether the vulnerable server is exposed.

Affected
Gallery - Private Photo Vault (Android app)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external storage.

Weakness
CWE-552
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.