FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

immich -- locked assets remain accessible through shared albums and links

Affected packages
immich <= 3.2.2

Details

VuXML ID fcc6917b-adbc-11f1-a655-3497f65b111b
Discovery 2026-08-28
Entry 2026-09-11
Modified 2026-09-16

VulnCheck reports:

Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset endpoint, allowing them to remain accessible through shared albums and links.

In 3.2.2 the single-asset endpoint still lacks the album removal that the bulk endpoint performs, and the album and shared link access checks still carry no visibility filter. Both code paths of the web interface use the bulk endpoint, so the state can only be reached by calling the API directly, and such assets stay visible only to those the owner already shares the album or the link with. The identifier was assigned by VulnCheck, not by the immich project, which has published no advisory and has not confirmed the report. NVD has not analysed the entry.

References

CVE Name CVE-2026-82272
URL https://github.com/immich-app/immich/issues/29526
URL https://nvd.nist.gov/vuln/detail/CVE-2026-82272