SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82272

MEDIUM · CVSS 6.5 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Immich versions up to 3.1.0 have a vulnerability that allows unauthorized access to locked assets through shared albums and links, despite the intended visibility restrictions. This flaw can lead to the exposure of sensitive data and metadata, making it critical for users managing private or sensitive content to prioritize updates. Organizations using Immich should address this issue promptly to mitigate potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82272
Severity
MEDIUM
CVSS
6.5
EPSS
0.25%

Original NVD Description

Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared albums and links. Attackers can read locked assets and their metadata by accessing existing shared albums or links, bypassing the locked visibility protection.