CVE-2026-72540: PhotoPrism PhotoPrism - Insecure Direct Object Reference
Published Aug 11, 2026
·Updated
Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.
Affected Software
1 affected component
PhotoPrism PhotoPrism<bb0b933
Event History
Aug 11, 2026
CVE Published
via MITRE·11:08 AM
Rejected
via MITRE·11:08 AM
Data Sourced
via NVD·12:17 PM
Description
Aug 17, 2026
Rejected
via MITRE·02:04 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-72540?
The severity of CVE-2026-72540 is rated as medium with a score of 4.3.
2
How do I fix CVE-2026-72540?
To fix CVE-2026-72540, ensure that the AlbumCover handler includes proper authorization checks before allowing access to album cover photos.
3
What is the risk associated with CVE-2026-72540?
The risk associated with CVE-2026-72540 is categorized as a risk level of 22, indicating potential exposure due to unauthorized access.
4
What type of vulnerability is CVE-2026-72540?
CVE-2026-72540 is classified as an insecure direct object reference vulnerability.
5
When was CVE-2026-72540 published?
CVE-2026-72540 was published on August 11, 2026.