CVE-2026-82272
Immich Locked Assets Remain Readable Through Albums and Shared Links
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared albums and links. Attackers can read locked assets and their metadata by accessing existing shared albums or links, bypassing the locked visibility protection.
| CWE | CWE-863 |
| Vendor | immich-app |
| Product | immich |
| Published | Aug 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for immich-app immich
Be the first to know when new medium vulnerabilities affecting immich-app immich are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
immich-app / immich
0 โค 3.1.0
References
github.com: https://github.com/immich-app/immich/issues/29526 github.com: https://github.com/immich-app/immich github.com: https://github.com/immich-app/immich/blob/6b478924b25768dfea304ec3b8273b8316903304/server/src/services/asset.service.ts github.com: https://github.com/immich-app/immich/blob/6b478924b25768dfea304ec3b8273b8316903304/server/src/repositories/access.repository.ts vulncheck.com: https://www.vulncheck.com/advisories/immich-locked-assets-remain-readable-through-albums-and-shared-links
Credits
๐ George Chen