CVE-2026-103532: immich-app Immich Shared Link Preview access.ts checkSharedLinkAccess improper authorization
A vulnerability has been found in immich-app Immich up to 2.7.5. This affects the function checkSharedLinkAccess of the file server/src/utils/access.ts of the component Shared Link Preview Handler. The manipulation of the argument Password leads to improper authorization. The attack may be initiated remotely. The reported GitHub issue was closed with the label "duplicate".
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
Immich deployments up to version 2.7.5 are reported as affected, specifically the Shared Link Preview Handler's checkSharedLinkAccess function in server/src/utils/access.ts.
What does an attacker need to exploit this issue?
The issue can be initiated remotely and requires manipulation of the Password argument. No privileges or user interaction are indicated by the supplied severity vector.
What is the likely impact of successful exploitation?
The supplied CVSS vector indicates low confidentiality impact, with no integrity or availability impact. The issue is categorized as improper authorization.
Is there a confirmed fix or workaround in the available information?
No fix version, workaround, or mitigation is provided. The referenced GitHub issue was closed as a duplicate, but the supplied data does not identify the duplicate issue or its resolution.