๐Ÿ” CVE Alert

CVE-2026-57945

MEDIUM 4.3

PhotoPrism - Unauthorized User Profile Modification via PUT /api/v1/users/{uid} Endpoint

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

PhotoPrism before 260601-a7d098548 contains a broken access control vulnerability that allows authenticated non-admin users to modify other users' profile information by sending requests to arbitrary user endpoints. Attackers can exploit the missing session-to-user identifier validation in the PUT users API endpoint to overwrite another user's profile details without authorization.

CWE CWE-639
Vendor photoprism
Product photoprism
Published Jun 29, 2026
Stay Ahead of the Next One

Get instant alerts for photoprism photoprism

Be the first to know when new medium vulnerabilities affecting photoprism photoprism are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

photoprism / photoprism
0 < 260601-a7d098548

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/photoprism/photoprism/releases/tag/260601-a7d098548 github.com: https://github.com/photoprism/photoprism/issues/5619 vulncheck.com: https://www.vulncheck.com/advisories/photoprism-unauthorized-user-profile-modification-via-put-api-v1-users-uid-endpoint

Credits

George Chen