MEDIUM 6.9 NVD
CVE-2026-103532
A vulnerability has been found in immich-app Immich up to 2.7.5. This affects the function checkSharedLinkAccess of the file server/src/utils/access.ts of the c
A vulnerability has been found in immich-app Immich up to 2.7.5. This affects the function checkSharedLinkAccess of the file server/src/utils/access.ts of the component Shared Link Preview Handler. The manipulation of the argument Password leads to improper authorization. The attack may be initiated remotely. The reported GitHub issue was closed with the label "duplicate".
References
- https://github.com/immich-app/immich/
- https://github.com/immich-app/immich/issues/29599
- https://vuldb.com/cve/CVE-2026-103532
- https://vuldb.com/submit/957120
- https://vuldb.com/vuln/412344
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-10-01 via NVD.
vulnfeed aggregates 9519 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.