Medium severity4.3NVD Advisory· Published Apr 9, 2026· Updated Apr 23, 2026
CVE-2026-39957
CVE-2026-39957
Description
Lychee is a free, open-source photo-management tool. Prior to 7.5.4, a SQL operator-precedence bug in SharingController::listAll() causes the orWhereNotNull('user_group_id') clause to escape the ownership filter applied by the when() block. Any authenticated non-admin user with upload permission who owns at least one album can retrieve all user-group-based sharing permissions across the entire instance, including private albums owned by other users. This vulnerability is fixed in 7.5.4.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/LycheeOrg/Lychee/commit/76a3f0513eca6458bf7f8c337c1ad65e59b22bcbnvdPatch
- github.com/LycheeOrg/Lychee/pull/4264nvdIssue TrackingPatch
- github.com/LycheeOrg/Lychee/security/advisories/GHSA-4v4c-g2jv-4g25nvdExploitVendor AdvisoryPatch
News mentions
0No linked articles in our index yet.