Improper Authorization Vulnerability in Immich-app by Immich
CVE-2026-103532

6.9MEDIUM

Key Information:

Vendor

Immich-app

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103532?

A vulnerability exists in the Immich-app affecting versions up to 2.7.5, specifically in the checkSharedLinkAccess function within the Shared Link Preview Handler. This flaw arises from improper handling of the 'Password' argument, allowing unauthorized access to shared links. Attackers may exploit this vulnerability remotely, posing a risk to data protection and user privacy. The issue has been logged on GitHub and is marked as a duplicate, highlighting the need for urgent attention to this access control weakness.

Affected Version(s)

Immich 2.7.0

Immich 2.7.1

Immich 2.7.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

geochen (VulDB User)
VulDB CNA Team
.