CVE-2026-59258: immich < 3.0.3 Shared Album Editor Ownership Takeover via updateUser
immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to modify member roles without owner-only restrictions. Attackers with editor access can demote the album owner to editor and promote themselves to owner in sequential requests, gaining full control including deletion and eviction capabilities.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
immichto a version that resolves this vulnerability.Fixed in 3.0.3 - Upgrade
Upgrade
immichto a version that resolves this vulnerability.Fixed in 3.0.3Patch Shared Album Editor Ownership Takeover via updateUser
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59258?
CVE-2026-59258 has a severity rating of high with a score of 8.3.
How do I fix CVE-2026-59258?
To fix CVE-2026-59258, upgrade to immich version 3.0.3 or later.
What type of vulnerability is CVE-2026-59258?
CVE-2026-59258 is a broken access control vulnerability affecting shared album editor permissions.
Can attackers exploit CVE-2026-59258 without being the album owner?
Yes, attackers with editor access can exploit CVE-2026-59258 to change member roles, including demoting the owner.
What should users of immich do regarding CVE-2026-59258?
Users of immich should ensure they are using version 3.0.3 or later to mitigate the risks associated with CVE-2026-59258.