Security Advisory

CVE-2026-59258

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-15 17:03:57
Last updated 2026-07-15 18:13:20
Assigner VulnCheck
CVSS score 7.2
State PUBLISHED

Description

immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to modify member roles without owner-only restrictions. Attackers with editor access can demote the album owner to editor and promote themselves to owner in sequential requests, gaining full control including deletion and eviction capabilities.