CVE-2026-108165
Deferred Deferred - Pending Action

Missing Authorization in Immich Exposes Locked Folder Metadata

Vulnerability report for CVE-2026-108165, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

Immich through 3.3.1 contains a missing authorization vulnerability in the partner synchronization stream that allows authenticated partners to read Locked Folder asset metadata because sync queries do not exclude Locked visibility. Attackers with an active partner relationship can call POST /api/sync/stream with PartnerAssetsV2 and PartnerAssetExifsV1 types to obtain GPS coordinates, capture times, descriptions and camera details.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
immich-app immich 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a missing authorization issue in Immich's partner synchronization feature. It allows authenticated partners to read metadata of assets in locked folders through the sync stream. The flaw occurs because sync queries do not exclude locked visibility assets, unlike direct access checks. Attackers can call specific API endpoints to retrieve sensitive data like GPS coordinates, timestamps, descriptions, and camera details.

Detection Guidance

To detect this vulnerability, monitor API requests to POST /api/sync/stream with PartnerAssetsV2 and PartnerAssetExifsV1 types. Check if responses include metadata for locked folder assets, such as GPS coordinates or timestamps.

Impact Analysis

If you use Immich's partner sync feature, an attacker with partner access could obtain private metadata from your locked assets. This includes location data, timestamps, and camera details without needing elevated permissions. The impact is data exposure but does not allow modification or deletion of assets.

Compliance Impact

This vulnerability could violate GDPR and HIPAA by exposing sensitive personal data (e.g., GPS coordinates, timestamps) without proper authorization. GDPR requires strict access controls for personal data, while HIPAA mandates protection of health-related metadata. The unauthorized data exposure may lead to compliance violations and legal consequences.

Mitigation Strategies

Update Immich to the latest patched version. Review and restrict partner access permissions. Add visibility filters to sync queries to exclude locked assets. Monitor for unauthorized API calls to /api/sync/stream.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108165. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart