Junglewise Threat Intelligence

CVE-2026-57945: PhotoPrism broken access control in user profile API

CVE-2026-57945 · Severity: medium · CVSS 4.3 · Published 2026-06-29

Executive brief

PhotoPrism, a popular AI-powered photo management application, contained a security flaw that allowed logged-in users to modify the profile information of other users. By sending specifically crafted requests to the application's programming interface (API), a non-privileged user could change details like display names on other accounts. While this did not allow attackers to take over accounts or change administrative settings, it could lead to unauthorized data modification and minor disruption for affected users.

Technical details

A broken access control vulnerability (CWE-639) exists in the PhotoPrism API's PUT /api/v1/users/{uid} endpoint. The application failed to validate that the authenticated user's session identifier matched the target user UID provided in the URL path. An authenticated, non-admin attacker could exploit this by sending PUT requests to other users' UIDs to overwrite profile fields. While privileged fields like 'Role' or 'SuperAdmin' are protected by separate server-side checks, informational profile details were susceptible to unauthorized modification. The issue was addressed in version 260601-a7d098548 by implementing an ownership check before processing the request.

Affected products

  • PhotoPrism PhotoPrism before 260601-a7d098548

Timeline

  • 2026-05-26: disclosed: Issue reported via GitHub by researcher geo-chen
  • 2026-06-01: patched: Fixed in release 260601-a7d098548
  • 2026-06-29: advisory: NVD publication date

References