CVE-2026-103532
Deferred Deferred - Pending Action

Improper Authorization in Immich Shared Link Preview

Vulnerability report for CVE-2026-103532, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulDB

Description

A vulnerability has been found in immich-app Immich up to 2.7.5. This affects the function checkSharedLinkAccess of the file server/src/utils/access.ts of the component Shared Link Preview Handler. The manipulation of the argument Password leads to improper authorization. The attack may be initiated remotely. The reported GitHub issue was closed with the label "duplicate".

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
immich-app immich to 2.7.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Immich up to version 2.7.5 allows unauthorized access to shared link resources. The issue occurs in the checkSharedLinkAccess function where the password argument is manipulated, bypassing proper authorization checks. Attackers can remotely access thumbnail images, full asset metadata, and EXIF/GPS data without providing the correct password.

Detection Guidance

Check Immich server logs for unauthorized access attempts to endpoints like /api/assets/:id/thumbnail, /api/assets/:id, or /api/albums/:id with valid shared link keys. Review if password-protected shared links bypass authentication by inspecting access.ts and SharedLinkService files for missing password checks in checkSharedLinkAccess().

Commands: grep -r 'checkSharedLinkAccess' /path/to/immich/server/src/; curl -v http://your-immich-server/api/assets/123/thumbnail?key=YOUR_SHARED_LINK_KEY

Impact Analysis

If you use Immich with password-protected shared links, attackers could view your private photos, videos, and associated metadata without authentication. This includes location data from GPS tags and other sensitive information embedded in files.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection requirements and HIPAA's privacy rules for protected health information. Organizations may face compliance violations if sensitive data is exposed through this flaw.

Mitigation Strategies

Update Immich to the latest version where this issue is fixed. If an update is unavailable, restrict access to shared link endpoints via network firewall rules or reverse proxy configurations. Temporarily disable shared link features until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103532. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart