CVE-2026-96271
7.1 HIGHpublic exploit availablePublished 2026-09-23 · Updated 2026-09-24
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows authenticated users to create share links for albums owned by other users. Attackers can supply arbitrary album IDs to generate working share tokens for victim albums, exposing photos and sub-albums to anyone with the link while retaining indefinite control over token settings.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Weaknesses
CWE-639
Public exploit & PoC references
- https://github.com/photoview/photoview
- https://github.com/photoview/photoview/blob/81affea602401c2f0207d955919ddcc0670a9222/api/graphql/models/actions/share_token_actions.go#L64-L82
- https://github.com/photoview/photoview/commit/20541762fe6d9e0ce363c3d4c55556e4ccdc57a2
- https://github.com/photoview/photoview/issues/1494
All references
- https://github.com/photoview/photoview
- https://github.com/photoview/photoview/blob/81affea602401c2f0207d955919ddcc0670a9222/api/graphql/models/actions/share_token_actions.go#L64-L82
- https://github.com/photoview/photoview/commit/20541762fe6d9e0ce363c3d4c55556e4ccdc57a2
- https://github.com/photoview/photoview/issues/1494
- https://www.vulncheck.com/advisories/photoview-through-2.4.0-authorization-bypass-via-sharealbum
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2025-71420PoC
- UNSCOREDCVE-2026-100177PoC
- MEDIUMCVE-2026-100531PoC
- LOWCVE-2026-100534PoC
- HIGHCVE-2026-100579PoC
- MEDIUMCVE-2026-100609PoC
- HIGHCVE-2026-100610PoC
- HIGHCVE-2026-100612PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.