What is CVE-2026-72540?
CVE-2026-72540 is an insecure direct object reference vulnerability in PhotoPrism up to commit bb0b933. It allows any user with a valid preview token to retrieve the original-resolution cover photo of any album without proper authorization checks. Users should update to the latest patched version immediately to mitigate this issue.
Azərbaycanca: CVE-2026-72540, PhotoPrism-də aşkarlanmış insecure direct object reference zəifliyidir. Bu zəiflik, sadəcə preview token-ə sahib istənilən istifadəçiyə, aid olmadığı albomların orijinal keyfiyyətli cover fotolarını əldə etməyə imkan verir. İstifadəçilər dərhal proqram təminatını ən son versiyaya yeniləməli və ya müvəqqəti olaraq təsirlənən funksionallığı məhdudlaşdırmalıdırlar.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
What does an attacker need to exploit CVE-2026-72540?
To exploit this vulnerability, an attacker only needs to have a valid preview token. With this token, they can retrieve the original-resolution cover photo of any album that does not belong to them.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.