MEDIUMVulnerability

CVE-2026-82272

Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared albums and links. Attackers can read locked assets and their metadata by accessing existing shared albums or links, bypassing the locked visibility protection.

Properties

severity
MEDIUM
score
6.5
cve_id
CVE-2026-82272
signal_observed_at
2026-09-23T22:44:40+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
published_at
2026-08-28T20:20:18.087
last_modified
2026-09-23T17:17:43.660

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82272 — Ninja Signal Threat Intelligence | Ninja Signal