Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-103532

MEDIUM NVD
CVSS Score 5.3
Severity MEDIUM
Published Oct 01, 2026
Vendor unknown

Description

A vulnerability has been found in immich-app Immich up to 2.7.5. This affects the function checkSharedLinkAccess of the file server/src/utils/access.ts of the component Shared Link Preview Handler. The manipulation of the argument Password leads to improper authorization. The attack may be initiated remotely. The reported GitHub issue was closed with the label "duplicate".

References