Junglewise Threat Intelligence

CVE-2026-82272: Immich locked asset visibility bypass in shared albums

CVE-2026-82272 · Severity: medium · CVSS 6.5 · Published 2026-08-28

Technologies: Immich. Vendors: Immich.

Executive brief

Immich is a self-hosted photo and video management application. A vulnerability allows users to access locked assets and their metadata through shared albums and links, even after those assets have been locked for privacy. An attacker with access to existing shared links or albums can view and retrieve locked photos and videos that should not be accessible.

Technical details

The vulnerability is an access control bypass in Immich through version 3.1.0 affecting the single-asset endpoint. When assets are locked through this endpoint, the locked visibility restriction is not properly enforced for assets already included in shared albums or public links. An unauthenticated attacker can access these locked assets by using any previously-created shared album or link, reading both the asset files and associated metadata. The issue occurs because the access control logic fails to check asset lock status when serving content through shared access paths.

Affected products

  • Immich Immich through 3.1.0

Timeline

  • 2026-08-28: disclosed

References

Related threats