Authorization Bypass in Photoview Product by Photoview
CVE-2026-96271
7.1HIGH
What is CVE-2026-96271?
Photoview versions up to 2.4.0 contain an authorization bypass vulnerability in the shareAlbum GraphQL mutation. This flaw allows authenticated users to create share links for albums owned by other users, leading to unauthorized access to private content. By inputting arbitrary album IDs, attackers can generate valid share tokens for a victim's albums, thereby exposing photos and related sub-albums to anyone with the link. This vulnerability also allows them to maintain indefinite control over the share token settings, potentially leading to further privacy breaches.
Affected Version(s)
photoview 0 <= 2.4.0
