Description
The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album owner's configuration. When an album owner shares a smart album with another user, that user's own folder configuration is used to determine which of the owner's files are searched — allowing them to discover files (name, file ID, and other metadata) in folders the album owner never intended to include in the shared album.

This requires the album owner to have shared a filter-based smart album with the attacker; it does not allow access to arbitrary users' files without such a share.
Published: 2026-09-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure of unintended file metadata
Action: Limit Shares
AI Analysis

Impact

The Photos app’s smart albums use the viewer’s folder configuration, not the owner’s, causing the recipient to discover the owner’s hidden file names, identifiers, and other metadata. This is an information‑disclosure flaw that reveals data the owner intended to keep private.

Affected Systems

Nextcloud Server, with the Photos app module, is affected. No specific version is provided in the CVE record.

Risk and Exploitability

The CVSS score of 6.5 denotes moderate severity, and the EPSS score of less than 1% indicates the vulnerability is not expected to be widely exploited. This flaw is not listed in CISA’s KEV catalog. Exploitation requires that the owner shares a filter-based smart album. Based on the description, the likely attack vector is the Photos web interface or API used after a legitimate sharing event.

Generated by OpenCVE AI on September 19, 2026 at 21:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Review all shared smart albums in the Photos app and remove any filter‑based albums that expose the owner’s files to unintended recipients.
  • Restrict or disable the use of filter‑based smart albums for sharing; configure permissions so that shared albums cannot invoke the viewer’s folder settings.
  • If a vendor patch or newer Nextcloud Server release addresses this issue, upgrade immediately to that version.
  • Monitor change logs and security advisories for Nextcloud to stay informed of any updates to this vulnerability.

Generated by OpenCVE AI on September 19, 2026 at 21:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sat, 19 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Title Photos App Shared Smart Albums Expose Unintended File Metadata

Sat, 19 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Title Photos App Shared Smart Albums Expose Unintended File Metadata

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Nextcloud
Nextcloud server
Vendors & Products Nextcloud
Nextcloud server

Fri, 18 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album owner's configuration. When an album owner shares a smart album with another user, that user's own folder configuration is used to determine which of the owner's files are searched — allowing them to discover files (name, file ID, and other metadata) in folders the album owner never intended to include in the shared album. This requires the album owner to have shared a filter-based smart album with the attacker; it does not allow access to arbitrary users' files without such a share.
Weaknesses CWE-284
References
Metrics cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Nextcloud Server
cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-09-18T19:40:43.484Z

Reserved: 2026-08-31T15:00:00.544Z

Link: CVE-2026-82985

cve-icon Vulnrichment

Updated: 2026-09-18T19:40:39.605Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T02:17:08.153

Modified: 2026-09-18T20:17:25.940

Link: CVE-2026-82985

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T21:45:16Z

Weaknesses