Improper Access Control in Immich Product by Immich App
CVE-2026-82272

7.1HIGH

Key Information:

Vendor

Immich-app

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-82272?

Immich versions prior to 3.1.0 are susceptible to issues with locked asset visibility. The application fails to enforce the correct access restrictions, allowing users to access locked assets through shared albums and links. This oversight exposes sensitive information, as attackers can read locked assets and their associated metadata by exploiting existing shared links, thereby circumventing the intended locked visibility protection measures.

Affected Version(s)

immich 0 <= 3.1.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.