Description
Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared albums and links. Attackers can read locked assets and their metadata by accessing existing shared albums or links, bypassing the locked visibility protection.
Published: 2026-08-28
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Immich versions up to 3.1.0 allow assets that are explicitly locked through the single‑asset endpoint to still be returned to a user via shared albums or shared links. The flaw removes the visibility restriction that an attacker would otherwise rely on, allowing anyone who can access a pre‑existing shared album or link to read the locked file data and its associated metadata. The weakness is a failure to enforce access control on locked assets.

Affected Systems

The vulnerability applies to the Immich application from the vendor immich-app. All installations running version 3.1.0 or earlier are affected; the specific functionality impacted is the asset locking mechanism exposed through album and link sharing.

Risk and Exploitability

The CVSS score of 7.1 indicates a high‑severity data‑exposure risk. EPSS information is unavailable, so exploitation likelihood cannot be quantified from available data, yet the flaw is exploitable by any party who can access an album or link that contains a locked asset. The vulnerability is not currently listed in CISA KEV, but the presence of a public GitHub discussion and a community advisory suggests that attackers may have identified the flaw. The exploit path requires prior exposure of a shared album or link; no additional privileges or software execution are required.

Generated by OpenCVE AI on August 28, 2026 at 22:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Immich to the latest release that includes the fixed asset‑locking enforcement.
  • Revoke all existing shared albums or links that reference locked assets until the update is installed.
  • Verify that locked assets are no longer accessible via shared albums or links by conducting a test read after patching.

Generated by OpenCVE AI on August 28, 2026 at 22:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Immich-app
Immich-app immich
Vendors & Products Immich-app
Immich-app immich

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared albums and links. Attackers can read locked assets and their metadata by accessing existing shared albums or links, bypassing the locked visibility protection.
Title Immich Locked Assets Remain Readable Through Albums and Shared Links
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Immich-app Immich
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-28T16:18:54.845Z

Reserved: 2026-08-28T11:12:39.173Z

Link: CVE-2026-82272

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T20:20:18.087

Modified: 2026-08-28T20:20:18.087

Link: CVE-2026-82272

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T22:15:04Z

Weaknesses