CVE-2026-82272

Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared albums and links. Attackers can read locked assets and their metadata by accessing existing shared albums or links, bypassing the locked visibility protection.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-28 20:20

Updated : 2026-08-31 19:17


NVD link : CVE-2026-82272

Mitre link : CVE-2026-82272

CVE.ORG link : CVE-2026-82272


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization