CVE-2026-103532 | immich-app Immich up to 2.7.5 Shared Link Preview access.ts checkSharedLinkAccess password improper authorization (Issue 29599)
A vulnerability, which was classified as problematic, has been found in immich-app Immich up to 2.7.5. This affects the function checkSharedLinkAccess of the file server/src/utils/access.ts of the component Shared Link Preview Handler. The manipulation of the argument Password leads to improper authorization.
This vulnerability is listed as CVE-2026-103532. The attack may be initiated remotely. There is no available exploit.
The reported GitHub issue was closed with the label “duplicate”.VulDB Recent EntriesRead More