Drupal · Photoswipe - Responsive Javascript Modal Image Gallery · CVE-2026-16645
**Name of the Vulnerable Software and Affected Versions**
PhotoSwipe - Responsive JavaScript Modal Image Gallery versions 0.0.0 through 3.2.0
**Description**
A missing authorization issue allows forceful browsing when viewing images using the photoswipe image gallery display formatter. The module fails to sufficiently check access permissions, which may allow unauthorized users to view images that should be restricted.
**Recommendations**
Update PhotoSwipe - Responsive JavaScript Modal Image Gallery to version 3.0.4 or later for Drupal 8.
Update PhotoSwipe - Responsive JavaScript Modal Image Gallery to version 3.2.0 or later for Drupal 9 and Drupal 10.