CVE-2026-96271
Photoview through 2.4.0 Authorization Bypass via shareAlbum
CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th
Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows authenticated users to create share links for albums owned by other users. Attackers can supply arbitrary album IDs to generate working share tokens for victim albums, exposing photos and sub-albums to anyone with the link while retaining indefinite control over token settings.
| CWE | CWE-639 |
| Vendor | photoview |
| Product | photoview |
| Published | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for photoview photoview
Be the first to know when new high vulnerabilities affecting photoview photoview are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None
Affected Versions
photoview / photoview
0 โค 2.4.0
References
github.com: https://github.com/photoview/photoview/issues/1494 github.com: https://github.com/photoview/photoview/blob/81affea602401c2f0207d955919ddcc0670a9222/api/graphql/models/actions/share_token_actions.go#L64-L82 github.com: https://github.com/photoview/photoview/commit/20541762fe6d9e0ce363c3d4c55556e4ccdc57a2 github.com: https://github.com/photoview/photoview vulncheck.com: https://www.vulncheck.com/advisories/photoview-through-2.4.0-authorization-bypass-via-sharealbum
Credits
๐ George Chen