๐Ÿ” CVE Alert

CVE-2026-96271

HIGH 7.1

Photoview through 2.4.0 Authorization Bypass via shareAlbum

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows authenticated users to create share links for albums owned by other users. Attackers can supply arbitrary album IDs to generate working share tokens for victim albums, exposing photos and sub-albums to anyone with the link while retaining indefinite control over token settings.

CWE CWE-639
Vendor photoview
Product photoview
Published Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for photoview photoview

Be the first to know when new high vulnerabilities affecting photoview photoview are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

photoview / photoview
0 โ‰ค 2.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/photoview/photoview/issues/1494 github.com: https://github.com/photoview/photoview/blob/81affea602401c2f0207d955919ddcc0670a9222/api/graphql/models/actions/share_token_actions.go#L64-L82 github.com: https://github.com/photoview/photoview/commit/20541762fe6d9e0ce363c3d4c55556e4ccdc57a2 github.com: https://github.com/photoview/photoview vulncheck.com: https://www.vulncheck.com/advisories/photoview-through-2.4.0-authorization-bypass-via-sharealbum

Credits

๐Ÿ” George Chen