Description
immich is a high performance self-hosted photo and video management solution. Prior to version 2.5.0, API keys can escalate their own permissions by calling the update endpoint, allowing a low-privilege API key to grant itself full administrative access to the system. Version 2.5.0 fixes the issue.
INFO
Published Date :
2026-01-29T17:12:43.543Z
Last Modified :
2026-01-29T21:25:38.711Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2026-23896 vulnerability.
| Vendors | Products |
|---|---|
| Futo |
|
| Immich-app |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-23896.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact