PT-2026-70115 · Unknown · Photoprism

·

CVE-2026-72540

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PhotoPrism versions prior to commit bb0b933
Description An insecure direct object reference (IDOR) occurs when an application provides direct access to objects based on user-supplied input. In this case, the AlbumCover handler fails to verify if the requesting user is authorized to access a specific album before serving the cover image. Consequently, any user possessing a valid preview token can enumerate and download original-resolution cover photos from albums belonging to other users.
Recommendations Update PhotoPrism to commit bb0b933 or a later version.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72540

Affected Products

Photoprism