MEDIUM 4.3 NVD

CVE-2026-72540

An insecure direct object reference vulnerability in PhotoPrism through commit bb0b933 allows any user with a valid preview token to retrieve the original-resol

An insecure direct object reference vulnerability in PhotoPrism through commit bb0b933 allows any user with a valid preview token to retrieve the original-resolution cover photo of any album. The AlbumCover handler does not verify that the requesting user is authorized to access the specified album before serving the cover image. An attacker with any valid preview token can enumerate and download album cover images belonging to other users.

References

Published: 2026-08-11 · Source: NVD · Feed updated: 2026-08-11
This medium severity vulnerability with a CVSS score of 4.3 was published on 2026-08-11 via NVD.
vulnfeed aggregates 9850 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.