Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in immich-app Immich up to 2.7.5. This affects the function checkSharedLinkAccess of the file server/src/utils/access.ts of the component Shared Link Preview Handler. The manipulation of the argument Password leads to improper authorization. The attack may be initiated remotely. The reported GitHub issue was closed with the label "duplicate". | |
| Title | immich-app Immich Shared Link Preview access.ts checkSharedLinkAccess improper authorization | |
| First Time appeared |
Immich
Immich immich |
|
| Weaknesses | CWE-266 CWE-285 |
|
| CPEs | cpe:2.3:a:immich:immich:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Immich
Immich immich |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-01T01:15:17.384Z
Reserved: 2026-09-30T19:06:55.475Z
Link: CVE-2026-103532
No data.
Status : Deferred
Published: 2026-10-01T02:16:53.600
Modified: 2026-10-01T02:16:53.767
Link: CVE-2026-103532
No data.
OpenCVE Enrichment
Updated: 2026-10-01T04:15:16Z