CVE-2026-103532

MEDIUM Status: Deferred

CVSS Scores

CVSS v3.x Base Score
5.3
MEDIUM
CVSS v2 Base Score
5.0
MEDIUM

Description

A vulnerability has been found in immich-app Immich up to 2.7.5. This affects the function checkSharedLinkAccess of the file server/src/utils/access.ts of the component Shared Link Preview Handler. The manipulation of the argument Password leads to improper authorization. The attack may be initiated remotely. The reported GitHub issue was closed with the label "duplicate".

Published
October 1, 2026 2:16 AM
Last Modified
October 1, 2026 2:16 AM
Source
[email protected]

Weaknesses (CWE)

CWE-266 CWE-285

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.