Vulnerability Description
PhotoPrism before 260601-a7d098548 contains a broken access control vulnerability that allows authenticated non-admin users to modify other users' profile information by sending requests to arbitrary user endpoints. Attackers can exploit the missing session-to-user identifier validation in the PUT users API endpoint to overwrite another user's profile details without authorization.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/photoprism/photoprism/issues/5619
- https://github.com/photoprism/photoprism/releases/tag/260601-a7d098548
- https://www.vulncheck.com/advisories/photoprism-unauthorized-user-profile-modifi
FAQ
What is CVE-2026-57945?
CVE-2026-57945 is a vulnerability with a CVSS score of 4.3 (MEDIUM). PhotoPrism before 260601-a7d098548 contains a broken access control vulnerability that allows authenticated non-admin users to modify other users' profile information by sending requests to arbitrary ...
How severe is CVE-2026-57945?
CVE-2026-57945 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-57945?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.