Loading market data...
← Back to CVE feed

CVE-2026-82272

MEDIUM CVSS 6.5 View on NVD ↗

Description

Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared albums and links. Attackers can read locked assets and their metadata by accessing existing shared albums or links, bypassing the locked visibility protection.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Published: Aug 28, 2026 20:20 UTC Modified: Aug 28, 2026 20:20 UTC