Medium severity4.3NVD Advisory· Published Aug 11, 2026· Updated Aug 11, 2026
CVE-2026-72540
CVE-2026-72540
Description
An insecure direct object reference vulnerability in PhotoPrism through commit bb0b933 allows any user with a valid preview token to retrieve the original-resolution cover photo of any album. The AlbumCover handler does not verify that the requesting user is authorized to access the specified album before serving the cover image. An attacker with any valid preview token can enumerate and download album cover images belonging to other users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <bb0b933
Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.