Junglewise Threat Intelligence

CVE-2026-59258: Immich broken access control in shared album user management

CVE-2026-59258 · Severity: high · CVSS 8.3 · Published 2026-07-15

Technologies: Immich-App Immich. Vendors: Immich.

Executive brief

Immich, a self-hosted photo and video management solution, contains a security flaw in how it handles shared album permissions. An authorized user who has been granted 'Editor' access to a shared album can exploit this bug to demote the original owner and take full control of the album. This allows the attacker to delete the album, evict the rightful owner, or modify all content within it.

Technical details

A broken access control vulnerability exists in the `PUT /albums/:id/user/:userId` endpoint in Immich. The application incorrectly authorizes this endpoint using the `Permission.AlbumShare` gate, which is granted to both owners and users with the 'Editor' role. Because the backend fails to verify if the requester is the actual owner or if the target of the update is the owner, an attacker with Editor permissions can demote the current owner to an Editor and then promote themselves to the 'Owner' role. This grants the attacker full administrative rights over the album, including deletion and member eviction. The issue is fixed in version 3.0.3.

Affected products

  • immich-app immich < 3.0.3

Timeline

  • 2026-06-09: disclosed: Initial report to developers via email
  • 2026-07-13: patched: Fix merged into main branch
  • 2026-07-15: advisory: CVE published and version 3.0.3 released

References

Related threats