CVE-2026-77884
—Unauthenticated HTTP File Server Exposes Android Storage in Gallery Private Photo Vault
Gallery – Private Photo Vault 1.0.41 for Android starts an unauthenticated HTTP server that listens on TCP port 8080 and is reachable from the local network, classified as CWE-552 (files or directories accessible to external parties). Any attacker on the same Wi-Fi or LAN segment can connect with no credentials and browse directory listings and download files from Android external storage. This defeats the app's core purpose of protecting private media, exposing stored photos and any other files in those directories to read access; the flaw is rated CVSS:4.0 7.1 (high) with an adjacent-network attack vector and high confidentiality impact. Users running version 1.0.41 are affected whenever the app's server is active and the device is on a shared network such as public or home Wi-Fi. No public proof of concept is known, there is no evidence of in-the-wild exploitation, and the CVE is not in CISA's KEV catalog.
What to do: Upgrade Gallery – Private Photo Vault past version 1.0.41 as soon as the vendor releases a fixed build, since 1.0.41 is the confirmed affected version. In the interim, avoid running the app on shared or untrusted Wi-Fi, enable AP/client isolation on routers you control, or uninstall the app and revoke its storage permissions. From another device on the same network, check whether the phone responds on TCP port 8080 to confirm whether the vulnerable server is exposed.
| Gallery - Private Photo Vault (Android app) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external storage.
- Weakness
- CWE-552
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.