CVE-2026-82272
largeAccess control flaw exposes locked assets via shared albums/links in Immich
Immich through version 3.1.0 contains an incorrect-authorization flaw (CWE-863) in which the locked-asset visibility control is not enforced when locked assets are also present in shared albums or shared links. The condition arises when a user locks assets via the single-asset endpoint, but those assets remain members of albums or links that have already been shared. Anyone with access to such a share - the CVSS vector indicates low privileges, e.g. a share recipient or holder of a shared link - can read the locked assets and their metadata, bypassing the lock; confidentiality is affected while integrity and availability are not. All self-hosted Immich deployments up to and including 3.1.0 are affected, but only where the locked-asset feature overlaps with existing shared albums or links. No public proof of concept, KEV listing, or known in-the-wild exploitation exists; EPSS estimates the 30-day exploitation probability at about 0.3%.
What to do: Upgrade to an Immich release newer than 3.1.0 once a patched version is published; no fixed version is specified in the available data. As an interim mitigation, remove locked assets from shared albums or shared links, or revoke/restrict those shares, until you can patch. Verify whether your instance actually uses the locked-asset feature, since the flaw only matters when locked assets appear in existing shares.
| Immich (self-hosted photo and video backup server) | through 3.1.0 (all versions up to and including 3.1.0) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared albums and links. Attackers can read locked assets and their metadata by accessing existing shared albums or links, bypassing the locked visibility protection.
- Weakness
- CWE-863
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.