{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-103532","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2026-09-30T19:06:55.475Z","datePublished":"2026-10-01T01:15:17.384Z","dateUpdated":"2026-10-01T18:58:33.513Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2026-10-01T01:15:17.384Z"},"title":"immich-app Immich Shared Link Preview access.ts checkSharedLinkAccess improper authorization","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-285","lang":"en","description":"Improper Authorization"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-266","lang":"en","description":"Incorrect Privilege Assignment"}]}],"affected":[{"vendor":"immich-app","product":"Immich","versions":[{"version":"2.7.0","status":"affected"},{"version":"2.7.1","status":"affected"},{"version":"2.7.2","status":"affected"},{"version":"2.7.3","status":"affected"},{"version":"2.7.4","status":"affected"},{"version":"2.7.5","status":"affected"}],"cpes":["cpe:2.3:a:immich:immich:*:*:*:*:*:*:*:*"],"modules":["Shared Link Preview Handler"]}],"descriptions":[{"lang":"en","value":"A vulnerability has been found in immich-app Immich up to 2.7.5. This affects the function checkSharedLinkAccess of the file server/src/utils/access.ts of the component Shared Link Preview Handler. The manipulation of the argument Password leads to improper authorization. The attack may be initiated remotely. The reported GitHub issue was closed with the label \"duplicate\"."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":6.9,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":5.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:C","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":5.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:C","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":5,"vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N/E:ND/RL:ND/RC:C"}}],"timeline":[{"time":"2026-09-30T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2026-09-30T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2026-09-30T21:12:03.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"geochen (VulDB User)","type":"reporter"},{"lang":"en","value":"VulDB CNA Team","type":"coordinator"}],"references":[{"url":"https://vuldb.com/vuln/412344","name":"VDB-412344 | immich-app Immich Shared Link Preview access.ts checkSharedLinkAccess improper authorization","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/412344/cti","name":"VDB-412344 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-103532","name":"CVE-2026-103532 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/957120","name":"Submit #957120 | https://github.com/immich-app immich v2.7.5 Missing Authorization","tags":["third-party-advisory"]},{"url":"https://github.com/immich-app/immich/issues/29599","tags":["issue-tracking"]},{"url":"https://github.com/immich-app/immich/","tags":["product"]}],"x_generator":["VulDB PVTS v202610"]},"adp":[{"references":[{"url":"https://github.com/immich-app/immich/issues/29599","tags":["exploit"]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-10-01T18:58:15.324035Z","id":"CVE-2026-103532","options":[{"Exploitation":"poc"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-10-01T18:58:33.513Z"}}]}}