VulnSea

Immich vulnerabilities

CVEs whose affected-version data names the Immich package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-103532Medium· 5.3
today

A vulnerability has been found in immich-app Immich up to 2.7.5

A vulnerability has been found in immich-app Immich up to 2.7.5. This affects the function checkSharedLinkAccess of the file server/src/utils/access.ts of the component Shared Link Preview Handler. The manipulation of the argument Passwo…

▾ Sunlitimmich-app · Immichvia NVD
CVE-2026-82272Medium· 6.5
1mo ago

Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared albums and links

Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared albums and links. Attackers can read locked assets and the…

▾ Sunlitimmich-app · immichEPSS 0.44%via NVD
CVE-2026-59258High· 8.3PoC
2mo ago

immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to modify member roles without owner-only restrictions

immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to modify member roles without owner-only restrictions. Attackers with editor access can dem…

▾ Midnightimmich-app · immichEPSS 0.46%via NVD
CVE-2026-25118High· 7.5
6mo ago

immich is a high performance self-hosted photo and video management solution

immich is a high performance self-hosted photo and video management solution. Prior to version 2.6.0, the Immich application is vulnerable to credential disclosure when a user authenticates to a shared album. During the authentication pr…

▾ Twilightfuto · immichEPSS 0.45%via NVD
Immich vulnerabilities (CVEs) · VulnSea