CVE-2026-82272
7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared albums and links. Attackers can read locked assets and their metadata by accessing existing shared albums or links, bypassing the locked visibility protection.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| immich-app | immich | 0 <= 3.1.0 | affected |
Weaknesses
- CWE-863: Incorrect Authorization
References
- https://github.com/immich-app/immich/issues/29526
- https://github.com/immich-app/immich
- https://github.com/immich-app/immich/blob/6b478924b25768dfea304ec3b8273b8316903304/server/src/services/asset.service.ts
- https://github.com/immich-app/immich/blob/6b478924b25768dfea304ec3b8273b8316903304/server/src/repositories/access.repository.ts
- https://www.vulncheck.com/advisories/immich-locked-assets-remain-readable-through-albums-and-shared-links
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.