CVE-2026-23896

immich is a high performance self-hosted photo and video management solution. Prior to version 2.5.0, API keys can escalate their own permissions by calling the update endpoint, allowing a low-privilege API key to grant itself full administrative access to the system. Version 2.5.0 fixes the issue.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:immich:immich:*:*:*:*:*:docker:*:*

History

10 Mar 2026, 18:00

Type Values Removed Values Added
Summary
  • (es) immich es una solución de gestión de fotos y videos autoalojada de alto rendimiento. Antes de la versión 2.5.0, las claves API pueden escalar sus propios permisos al llamar al endpoint de actualización, permitiendo que una clave API de bajo privilegio se otorgue acceso administrativo completo al sistema. La versión 2.5.0 corrige el problema.
References () https://github.com/immich-app/immich/security/advisories/GHSA-237r-x578-h5mv - () https://github.com/immich-app/immich/security/advisories/GHSA-237r-x578-h5mv - Exploit, Vendor Advisory
CPE cpe:2.3:a:immich:immich:*:*:*:*:*:docker:*:*
First Time Immich
Immich immich
CWE NVD-CWE-noinfo

29 Jan 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-29 18:16

Updated : 2026-03-10 18:00


NVD link : CVE-2026-23896

Mitre link : CVE-2026-23896

CVE.ORG link : CVE-2026-23896


JSON object : View

Products Affected

immich

  • immich
CWE
CWE-269

Improper Privilege Management

NVD-CWE-noinfo