CVE-2026-25118: immich-server: Insecure Transmission of Authentication Credentials via Password Parameter in HTTP Request Query String When Accessing Shared Albums
immich is a high performance self-hosted photo and video management solution. Prior to version 2.6.0, the Immich application is vulnerable to credential disclosure when a user authenticates to a shared album. During the authentication process, the application transmits the album password within the URL query parameters in a GET request to /api/shared-links/me. This exposes the password in browser history, proxy and server logs, and referrer headers, allowing unintended disclosure of authentication credentials. The impact of this vulnerability is the potential compromise of shared album access and unauthorized exposure of sensitive user data. This issue has been patched in version 2.6.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
immichto a version that resolves this vulnerability.Fixed in 2.6.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25118?
CVE-2026-25118 has a high severity level due to the insecure transmission of authentication credentials.
How do I fix CVE-2026-25118?
To fix CVE-2026-25118, upgrade your immich-server to version 2.6.0 or later.
What is the impact of CVE-2026-25118 on immich-server?
CVE-2026-25118 can lead to unauthorized access to shared albums due to credential exposure.
Is my version of immich-server affected by CVE-2026-25118?
If you are using immich-server version prior to 2.6.0, you are affected by CVE-2026-25118.
What does CVE-2026-25118 entail regarding data protection?
CVE-2026-25118 exposes user authentication credentials in HTTP request query strings, compromising data protection.