Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared albums and links. Attackers can read locked assets and their metadata by accessing existing shared albums or links, bypassing the locked visibility protection.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-28 20:20
Updated : 2026-08-31 19:17
NVD link : CVE-2026-82272
Mitre link : CVE-2026-82272
CVE.ORG link : CVE-2026-82272
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
