PT-2026-60251 · Git+1 · Immich
CVSS v3.1
8.3
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
immich versions prior to 3.0.3
Description
Broken access control exists in the 'PUT /albums/:id/user/:userId' endpoint. This issue allows users with editor permissions on a shared album to modify member roles because owner-only restrictions are not properly enforced. An attacker with editor access can execute sequential requests to demote the album owner to an editor and promote themselves to the owner role, granting them full control over the album, including the ability to delete content and evict other members.
Recommendations
Update to version 3.0.3 or later.
Restrict access to the 'PUT /albums/:id/user/:userId' endpoint to prevent unauthorized role modifications.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Immich