CVE-2026-103532 | immich-app Immich up to 2.7.5 Shared Link Preview access.ts checkSharedLinkAccess password improper authorization (Issue 29599)

SecurityVulns

A vulnerability, which was classified as problematic, has been found in immich-app Immich up to 2.7.5. This affects the function checkSharedLinkAccess of the file server/src/utils/access.ts of the component Shared Link Preview Handler. The manipulation of the argument Password leads to improper authorization.

This vulnerability is listed as CVE-2026-103532. The attack may be initiated remotely. There is no available exploit.

The reported GitHub issue was closed with the label “duplicate”.VulDB Recent EntriesRead More