CVE-2026-77884: Brain Trust Gallery - Private Photo Vault

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external storage.

Affected products

  • Brain Trust Gallery - Private Photo Vault: version 1.0.41 only

Published 2026-09-14. Last modified 2026-09-18.