CVE-2026-108165: Immich through 3.3.1 Missing Authorization in Partner Sync Exposes Locked Folder Metadata
Immich through 3.3.1 contains a missing authorization vulnerability in the partner synchronization stream that allows authenticated partners to read Locked Folder asset metadata because sync queries do not exclude Locked visibility. Attackers with an active partner relationship can call POST /api/sync/stream with PartnerAssetsV2 and PartnerAssetExifsV1 types to obtain GPS coordinates, capture times, descriptions and camera details.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated and have an active partner relationship with the affected Immich user. Unauthenticated users and authenticated users without that partner relationship are not described as able to access the data.
What information can be exposed?
The affected sync stream can expose metadata for assets in Locked Folders, including GPS coordinates, capture times, descriptions, and camera details. The provided information describes metadata exposure, not access to the underlying asset files.
What request is involved in exploitation?
Exploitation uses POST /api/sync/stream with the PartnerAssetsV2 and PartnerAssetExifsV1 sync types. The issue occurs because the partner sync queries do not exclude assets with Locked visibility.