CVE-2026-23896

immich is a high performance self-hosted photo and video management solution. Prior to version 2.5.0, API keys can escalate their own permissions by calling the update endpoint, allowing a low-privilege API key to grant itself full administrative access to the system. Version 2.5.0 fixes the issue.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:futo:immich:*:*:*:*:*:docker:*:*

History

15 Apr 2026, 18:55

Type Values Removed Values Added
First Time Futo immich
Futo
CPE cpe:2.3:a:immich:immich:*:*:*:*:*:docker:*:* cpe:2.3:a:futo:immich:*:*:*:*:*:docker:*:*

10 Mar 2026, 18:00

Type Values Removed Values Added
CWE NVD-CWE-noinfo
Summary
  • (es) immich es una solución de gestión de fotos y videos autoalojada de alto rendimiento. Antes de la versión 2.5.0, las claves API pueden escalar sus propios permisos al llamar al endpoint de actualización, permitiendo que una clave API de bajo privilegio se otorgue acceso administrativo completo al sistema. La versión 2.5.0 corrige el problema.
References () https://github.com/immich-app/immich/security/advisories/GHSA-237r-x578-h5mv - () https://github.com/immich-app/immich/security/advisories/GHSA-237r-x578-h5mv - Exploit, Vendor Advisory
CPE cpe:2.3:a:immich:immich:*:*:*:*:*:docker:*:*
First Time Immich
Immich immich

29 Jan 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-29 18:16

Updated : 2026-04-15 18:55


NVD link : CVE-2026-23896

Mitre link : CVE-2026-23896

CVE.ORG link : CVE-2026-23896


JSON object : View

Products Affected

futo

  • immich
CWE
CWE-269

Improper Privilege Management

NVD-CWE-noinfo