CVE-2026-96271

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
7.1
HIGH

Description

Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows authenticated users to create share links for albums owned by other users. Attackers can supply arbitrary album IDs to generate working share tokens for victim albums, exposing photos and sub-albums to anyone with the link while retaining indefinite control over token settings.

Published
September 23, 2026 1:16 AM
Last Modified
September 23, 2026 1:16 AM
Source
[email protected]

Weaknesses (CWE)

CWE-639

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.