Metrics
Affected Vendors & Products
No reference.
Mon, 17 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | PhotoPrism PhotoPrism - Insecure Direct Object Reference | |
| Metrics |
ssvc
|
Mon, 17 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Mon, 17 Aug 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An insecure direct object reference vulnerability in PhotoPrism through commit bb0b933 allows any user with a valid preview token to retrieve the original-resolution cover photo of any album. The AlbumCover handler does not verify that the requesting user is authorized to access the specified album before serving the cover image. An attacker with any valid preview token can enumerate and download album cover images belonging to other users. | Red Hat CNA-LR concluded that this CVE is not valid. |
Tue, 11 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Photoprism
Photoprism photoprism |
|
| Vendors & Products |
Photoprism
Photoprism photoprism |
Tue, 11 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An insecure direct object reference vulnerability in PhotoPrism through commit bb0b933 allows any user with a valid preview token to retrieve the original-resolution cover photo of any album. The AlbumCover handler does not verify that the requesting user is authorized to access the specified album before serving the cover image. An attacker with any valid preview token can enumerate and download album cover images belonging to other users. | |
| Title | PhotoPrism PhotoPrism - Insecure Direct Object Reference | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: REJECTED
Assigner: TuranSec
Published: 2026-08-11T11:08:04.426Z
Updated: 2026-08-17T14:04:05.864Z
Reserved: 2026-08-10T10:32:49.080Z
Link: CVE-2026-72540
Updated:
Status : Rejected
Published: 2026-08-11T12:17:39.347
Modified: 2026-08-17T14:20:22.083
Link: CVE-2026-72540
No data.