---
id: CVE-2026-77884
title: >-
  Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server
  that is reachable from the local network
summary: >-
  Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server
  that is reachable from the local network. The server listens on TCP port 8080
  and serves files and directory listings from Android external storage.
severity: high
cvss: 7.1
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-552
vendor: Brain Trust
product: Gallery - Private Photo Vault
affected:
  - gallery_-_private_photo_vault 1.0.41
published: '2026-09-14'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:44:10.957'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77884'
references:
  - url: 'https://fluidattacks.com/advisories/suicide'
    label: help@fluidattacks.com
  - url: 'https://play.google.com/store/apps/details?id=bt.photo.video.lock.album'
    label: help@fluidattacks.com
  - url: 'https://fluidattacks.com/advisories/suicide'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00251
epssPercentile: 0.14593
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T19:03:57.861203Z'
cvssSource: cna
ingestedAt: '2026-09-14T19:13:23.483Z'
---

## Overview

Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external storage.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
