PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108165 immich-app CVE debrief

CVE-2026-108165 is a missing authorization vulnerability in Immich through version 3.3.1. This vulnerability allows authenticated partners to read Locked Folder asset metadata due to sync queries not excluding Locked visibility. The issue arises in the partner synchronization stream, enabling attackers with an active partner relationship to access certain metadata, such as GPS coordinates, capture times, descriptions, and camera details. Defenders should assess exposure and verify partner synchronization stream authorization to prevent unauthorized access to Locked Folder asset metadata.

Vendor
immich-app
Product
immich
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders and security teams responsible for Immich deployments should assess exposure and verify partner synchronization stream authorization to prevent unauthorized access to Locked Folder asset metadata.

Why it matters

CVE-2026-108165 is a medium-severity vulnerability in Immich that allows authenticated partners to access Locked Folder asset metadata due to a missing authorization issue. Defenders should prioritize verifying partner synchronization stream authorization and ensuring Locked Folder asset metadata is properly secured.

  • Authenticated partners can access Locked Folder asset metadata, including GPS coordinates, capture times, descriptions, and camera details.
  • The vulnerability allows for potential information disclosure and unauthorized access to sensitive metadata.
  • Defenders should verify partner synchronization stream authorization to prevent exploitation.
  • Remediation priority is medium, as the vulnerability has a CVSS score of 5.3 and is publicly disclosed.

Technical summary

The CVE-2026-108165 vulnerability in Immich allows authenticated partners to read Locked Folder asset metadata due to a missing authorization issue in the partner synchronization stream. This issue arises because sync queries do not exclude Locked visibility, enabling attackers to access metadata such as GPS coordinates, capture times, descriptions, and camera details. The vulnerability has a CVSS score of 5.3 and is classified as medium-severity. Defenders should prioritize verifying partner synchronization stream authorization and ensuring Locked Folder asset metadata is properly secured.

Defensive priority

Defenders should prioritize verifying partner synchronization stream authorization and ensuring Locked Folder asset metadata is properly secured.

Recommended defensive actions

  • Verify partner synchronization stream authorization to prevent unauthorized access to Locked Folder asset metadata.
  • Ensure Locked Folder asset metadata is properly secured and access is restricted to authorized users.
  • Review and update Immich configurations to prevent exploitation of the missing authorization vulnerability.
  • Confirm whether affected Immich deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed Immich systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed Immich assets that need extra review.
  • Track exceptions, retest remediated Immich assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide details on the missing authorization vulnerability in Immich, allowing authenticated partners to access Locked Folder asset metadata. The vulnerability is confirmed in Immich through version 3.3.1. Official CVE Program and NVD records detail the issue, and source references provide additional context on the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108165 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108165

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108165 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108165

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.