CVE-2026-108165 | immich-app Immich up to 3.3.1 Partner Synchronization Stream /api/sync/stream authorization
A vulnerability marked as problematic has been reported in immich-app Immich up to 3.3.1. The impacted element is an unknown function of the file /api/sync/stream of the component Partner Synchronization Stream. This manipulation causes missing authorization.
This vulnerability appears as CVE-2026-108165. The attack may be initiated remotely. There is no available exploit.VulDB Recent EntriesRead More