PT-2026-2295 · Lychee · Lychee

Chakradhar1228

·

Publicado

2026-01-12

·

Atualizado

2026-01-12

·

CVE-2026-22784

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Lychee versions prior to 7.1.0
Description Lychee is a free, open-source photo-management tool. A flaw exists in the album password unlock functionality that could allow users to gain unauthorized access to other users' password-protected albums. When a user unlocks a password-protected public album, the system automatically unlocks all other public albums sharing the same password, bypassing authorization controls.
Recommendations Update to version 7.1.0 or later.

Exploit

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-22784
GHSA-JJ56-2C54-4F25

Produtos afetados

Lychee