CVE-2026-72540

MEDIUMCVSS 4.3/10

Last modified

CVE-2026-72540 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. An insecure direct object reference vulnerability in PhotoPrism through commit bb0b933 allows any user with a valid preview token to retrieve the original-resolution cover photo of any album. The AlbumCover handler does not verify that the requesting user is authorized to access the specified album before serving the cover image.

Description

An insecure direct object reference vulnerability in PhotoPrism through commit bb0b933 allows any user with a valid preview token to retrieve the original-resolution cover photo of any album. The AlbumCover handler does not verify that the requesting user is authorized to access the specified album before serving the cover image. An attacker with any valid preview token can enumerate and download album cover images belonging to other users.

Metrics

CVSS 3.1
4.3/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
PhotoPrismPhotoPrism<= bb0b933

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-72540?
An insecure direct object reference vulnerability in PhotoPrism through commit bb0b933 allows any user with a valid preview token to retrieve the original-resolution cover photo of any album. The AlbumCover handler does not verify that the requesting user is authorized to access the specified album before serving the cover image. An attacker with any valid preview token can enumerate and download album cover images belonging to other users.
How severe is CVE-2026-72540?
CVE-2026-72540 has a CVSS score of 4.3/10 (MEDIUM severity).
How do I fix CVE-2026-72540?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-72540?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST