CVE-2026-23896: immich API Key Privilege Escalation vulnerability
immich is a high performance self-hosted photo and video management solution. Prior to version 2.5.0, API keys can escalate their own permissions by calling the update endpoint, allowing a low-privilege API key to grant itself full administrative access to the system. Version 2.5.0 fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23896?
CVE-2026-23896 is classified as a high severity vulnerability due to the risk of privilege escalation.
How do I fix CVE-2026-23896?
To fix CVE-2026-23896, update your immich installation to version 2.5.0 or later.
What software is affected by CVE-2026-23896?
CVE-2026-23896 affects immich versions prior to 2.5.0.
What does CVE-2026-23896 exploit?
CVE-2026-23896 exploits the ability of low-privilege API keys to escalate their permissions via the update endpoint.
Can CVE-2026-23896 lead to unauthorized access?
Yes, CVE-2026-23896 can allow unauthorized users to gain full administrative access if not mitigated.