๐Ÿ” CVE Alert

CVE-2026-39957

UNKNOWN 0.0

Lychee has Broken Access Control in SharingController::listAll() leaks private album sharing metadata to unauthorized users

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Lychee is a free, open-source photo-management tool. Prior to 7.5.4, a SQL operator-precedence bug in SharingController::listAll() causes the orWhereNotNull('user_group_id') clause to escape the ownership filter applied by the when() block. Any authenticated non-admin user with upload permission who owns at least one album can retrieve all user-group-based sharing permissions across the entire instance, including private albums owned by other users. This vulnerability is fixed in 7.5.4.

CWE CWE-863
Vendor lycheeorg
Product lychee
Published Apr 9, 2026
Last Updated Apr 9, 2026
Stay Ahead of the Next One

Get instant alerts for lycheeorg lychee

Be the first to know when new unknown vulnerabilities affecting lycheeorg lychee are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

LycheeOrg / Lychee
< 7.5.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/LycheeOrg/Lychee/security/advisories/GHSA-4v4c-g2jv-4g25 github.com: https://github.com/LycheeOrg/Lychee/pull/4264 github.com: https://github.com/LycheeOrg/Lychee/commit/76a3f0513eca6458bf7f8c337c1ad65e59b22bcb