CVE-2026-103532 MEDIUM

CVE-2026-103532: immich-app Immich Shared Link Preview access.ts checkSharedLinkAccess improper authorization

Vendor Immich-App
Product Immich
Weakness CWE-285
Published October 1, 2026
Last update October 1, 2026

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X

What the vulnerability does

01Description

A vulnerability has been found in immich-app Immich up to 2.7.5. This affects the function checkSharedLinkAccess of the file server/src/utils/access.ts of the component Shared Link Preview Handler. The manipulation of the argument Password leads to improper authorization. The attack may be initiated remotely. The reported GitHub issue was closed with the label "duplicate".

Key dates

02Disclosure timeline

October 1, 2026 CVE published

Related vulnerabilities

04Related CVE