Medium severity6.5NVD Advisory· Published Aug 28, 2026
CVE-2026-82272
CVE-2026-82272
Description
Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared albums and links. Attackers can read locked assets and their metadata by accessing existing shared albums or links, bypassing the locked visibility protection.
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/immich-app/immich/blob/6b478924b25768dfea304ec3b8273b8316903304/server/src/repositories/access.repository.tsnvd
- github.com/immich-app/immich/blob/6b478924b25768dfea304ec3b8273b8316903304/server/src/services/asset.service.tsnvd
- github.com/immich-app/immich/issues/29526nvd
- www.vulncheck.com/advisories/immich-locked-assets-remain-readable-through-albums-and-shared-linksnvd
News mentions
0No linked articles in our index yet.