---
id: CVE-2026-82272
title: >-
  Immich through 3.1.0 fails to properly enforce locked asset visibility when
  assets are locked through the single-asset endpoint, allowing them to remain
  accessible through shared albums and links
summary: >-
  Immich through 3.1.0 fails to properly enforce locked asset visibility when
  assets are locked through the single-asset endpoint, allowing them to remain
  accessible through shared albums and links. Attackers can read locked assets
  and the…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-863
published: '2026-08-28'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:17:43.660'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82272'
references:
  - url: 'https://github.com/immich-app/immich'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/immich-app/immich/blob/6b478924b25768dfea304ec3b8273b8316903304/server/src/repositories/access.repository.ts
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/immich-app/immich/blob/6b478924b25768dfea304ec3b8273b8316903304/server/src/services/asset.service.ts
    label: disclosure@vulncheck.com
  - url: 'https://github.com/immich-app/immich/issues/29526'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/immich-locked-assets-remain-readable-through-albums-and-shared-links
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00436
epssPercentile: 0.35165
ingestedAt: '2026-09-23T17:28:14.812Z'
vendor: immich-app
product: immich
affected:
  - immich <= 3.1.0
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-31T16:23:31.351711Z'
---

## Overview

Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared albums and links. Attackers can read locked assets and their metadata by accessing existing shared albums or links, bypassing the locked visibility protection.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
