Sceawere
Vulnerability Detail
CVE-2026-108165UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Immich Missing Authorization Metadata Leak
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 2h ago
- Vendor
- immich-app
- Product
- immich
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Immich through 3.3.1 contains a missing authorization vulnerability in the partner synchronization stream that allows authenticated partners to read Locked Folder asset metadata because sync queries do not exclude Locked visibility. Attackers with an active partner relationship can call POST /api/sync/stream with PartnerAssetsV2 and PartnerAssetExifsV1 types to obtain GPS coordinates, capture times, descriptions and camera details.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-10T14:16:37.800Z",
"pubdate": "2026-10-10T14:16:37.800Z",
"executiveSummary": "Immich versions through 3.3.1 are susceptible to a missing authorization vulnerability within the partner synchronization stream. This security flaw enables authenticated partners to gain unauthorized access to metadata belonging to assets stored in a user's Locked Folder.\nThe vulnerability is categorized as a failure to enforce access controls during the synchronization process. Because the sync queries lack an exclusion mechanism for 'Locked' visibility status, the application inadvertently exposes sensitive information that should be restricted.\nThe impact includes the unauthorized disclosure of asset metadata, specifically GPS coordinates, capture timestamps, descriptive metadata, and camera hardware details. This exposure poses a significant privacy risk to users, as granular location and situational data can be exfiltrated without the owner's consent.\nExploitation requires an active and valid partner relationship between the attacker and the victim within the Immich instance. An attacker must possess legitimate authentication credentials for the partner account to successfully invoke the compromised API endpoints.\nThis issue highlights a critical oversight in authorization logic where secondary visibility states—specifically the 'Locked' attribute—are ignored during cross-user synchronization requests. Risk implications are moderate to high, depending on the sensitivity of the user's hidden assets.",
"technicalDetails": "The vulnerability resides in the partner synchronization stream component of Immich, specifically affecting the processing logic of the /api/sync/stream endpoint. The root cause is an improper authorization check that fails to validate the visibility constraints of assets requested during synchronization sessions.\nWhen a partner relationship is established, the application allows users to synchronize asset data. The /api/sync/stream endpoint accepts various types, including PartnerAssetsV2 and PartnerAssetExifsV1. These structures are intended to return metadata for shared assets; however, the backend query logic fails to filter out records marked with a 'Locked' status.\nAn attacker with a pre-existing partner relationship can exploit this by crafting a POST request to /api/sync/stream. By specifying the PartnerAssetsV2 or PartnerAssetExifsV1 types, the attacker triggers an unconstrained database query. Because the application logic does not incorporate a conditional filter to check for the 'Locked' property during this fetch operation, the server returns the full metadata payload for all assets, including those explicitly hidden by the partner.\nThe attack flow proceeds as follows: 1) The attacker authenticates to their own Immich account. 2) The attacker ensures an active partner relationship exists with the victim. 3) The attacker sends a POST request to /api/sync/stream with a body specifying the desired types (PartnerAssetsV2 and PartnerAssetExifsV1). 4) The Immich server parses the request, fails to verify if the individual assets within the sync scope are 'Locked', and retrieves the metadata from the database. 5) The server serializes the comprehensive metadata—including GPS coordinates, precise capture timestamps, descriptive tags, and camera hardware strings—into the JSON response body.\nThe vulnerability affects all versions of Immich up to and including 3.3.1. The flaw is confined to the server-side API implementation where the synchronization query building logic exists. Since this occurs within the authenticated partner context, no additional escalation of privileges is required; the attacker operates within their authorized partner scope, yet extracts unauthorized data due to a failure in granular object-level authorization."
}