Vulnerability Description
Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared albums and links. Attackers can read locked assets and their metadata by accessing existing shared albums or links, bypassing the locked visibility protection.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/immich-app/immich
- https://github.com/immich-app/immich/blob/6b478924b25768dfea304ec3b8273b83169033
- https://github.com/immich-app/immich/blob/6b478924b25768dfea304ec3b8273b83169033
- https://github.com/immich-app/immich/issues/29526
- https://www.vulncheck.com/advisories/immich-locked-assets-remain-readable-throug
FAQ
What is CVE-2026-82272?
CVE-2026-82272 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared albums and links. Att...
How severe is CVE-2026-82272?
CVE-2026-82272 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-82272?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.