๐Ÿ” CVE Alert

CVE-2026-82272

MEDIUM 6.5

Immich Locked Assets Remain Readable Through Albums and Shared Links

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared albums and links. Attackers can read locked assets and their metadata by accessing existing shared albums or links, bypassing the locked visibility protection.

CWE CWE-863
Vendor immich-app
Product immich
Published Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for immich-app immich

Be the first to know when new medium vulnerabilities affecting immich-app immich are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

immich-app / immich
0 โ‰ค 3.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/immich-app/immich/issues/29526 github.com: https://github.com/immich-app/immich github.com: https://github.com/immich-app/immich/blob/6b478924b25768dfea304ec3b8273b8316903304/server/src/services/asset.service.ts github.com: https://github.com/immich-app/immich/blob/6b478924b25768dfea304ec3b8273b8316903304/server/src/repositories/access.repository.ts vulncheck.com: https://www.vulncheck.com/advisories/immich-locked-assets-remain-readable-through-albums-and-shared-links

Credits

๐Ÿ” George Chen