Authorization Bypass in Photoview Product by Photoview
CVE-2026-96271

7.1HIGH

Key Information:

Vendor

Photoview

Status
Vendor
CVE Published:
23 September 2026

What is CVE-2026-96271?

Photoview versions up to 2.4.0 contain an authorization bypass vulnerability in the shareAlbum GraphQL mutation. This flaw allows authenticated users to create share links for albums owned by other users, leading to unauthorized access to private content. By inputting arbitrary album IDs, attackers can generate valid share tokens for a victim's albums, thereby exposing photos and related sub-albums to anyone with the link. This vulnerability also allows them to maintain indefinite control over the share token settings, potentially leading to further privacy breaches.

Affected Version(s)

photoview 0 <= 2.4.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.