PT-2026-97122 · Photoview · Photoview

·

CVE-2026-96271

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Photoview versions prior to 2.4.1
Description An authorization bypass exists in the shareAlbum GraphQL mutation. This flaw allows authenticated users to generate share tokens for albums they do not own by providing arbitrary album IDs. Consequently, photos and sub-albums are exposed to anyone possessing the link, and the attacker maintains indefinite control over the token settings.
Recommendations Update Photoview to version 2.4.1 or later. As a temporary mitigation, restrict access to the shareAlbum GraphQL mutation.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96271

Affected Products

Photoview