immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to modify member roles without owner-only restrictions. Attackers with editor access can demote the album owner to editor and promote themselves to owner in sequential requests, gaining full control including deletion and eviction capabilities.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-15 18:16
Updated : 2026-09-17 18:16
NVD link : CVE-2026-59258
Mitre link : CVE-2026-59258
CVE.ORG link : CVE-2026-59258
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
