FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

immich -- locked assets remain accessible through shared albums and links

Affected packages
immich <= 3.2.0

Details

VuXML ID fcc6917b-adbc-11f1-a655-3497f65b111b
Discovery 2026-08-28
Entry 2026-09-11

NVD reports:

Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared albums and links.

The single-asset code path still lacks the album removal that the bulk path performs, so 3.2.0 is affected as well. Upstream has not released a fix yet.

References

CVE Name CVE-2026-82272
URL https://github.com/immich-app/immich/issues/29526
URL https://nvd.nist.gov/vuln/detail/CVE-2026-82272