Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 15 Apr 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Futo
Futo immich |
|
| CPEs | cpe:2.3:a:futo:immich:*:*:*:*:*:docker:*:* | |
| Vendors & Products |
Immich
Immich immich |
Futo
Futo immich |
Tue, 10 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Immich
Immich immich |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:immich:immich:*:*:*:*:*:docker:*:* | |
| Vendors & Products |
Immich
Immich immich |
Fri, 30 Jan 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Immich-app
Immich-app immich |
|
| Vendors & Products |
Immich-app
Immich-app immich |
Thu, 29 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 29 Jan 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | immich is a high performance self-hosted photo and video management solution. Prior to version 2.5.0, API keys can escalate their own permissions by calling the update endpoint, allowing a low-privilege API key to grant itself full administrative access to the system. Version 2.5.0 fixes the issue. | |
| Title | immich API Key Privilege Escalation vulnerability | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-29T21:25:38.711Z
Reserved: 2026-01-16T21:02:02.903Z
Link: CVE-2026-23896
Updated: 2026-01-29T21:25:33.128Z
Status : Analyzed
Published: 2026-01-29T18:16:14.970
Modified: 2026-04-15T18:55:12.210
Link: CVE-2026-23896
No data.
OpenCVE Enrichment
Updated: 2026-04-18T01:30:16Z