CVE-2026-57943
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
29/06/2026
Last modified:
14/07/2026
Description
LibrePhotos before 1.0.0 contains a broken object level authorization vulnerability in the SetPhotosShared endpoint that allows authenticated users to grant themselves access to other users' private photos by bypassing ownership validation. Attackers can manipulate shared_to relations without proper owner checks to read arbitrary private photos belonging to other users.
Impact
Base Score 4.0
6.00
Severity 4.0
MEDIUM
Base Score 3.x
5.90
Severity 3.x
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/LibrePhotos/librephotos/commit/325bd1f5fda71c6d56737aa09cfce0cb8106675a
- https://github.com/LibrePhotos/librephotos/issues/1860
- https://github.com/LibrePhotos/librephotos/pull/1866
- https://github.com/LibrePhotos/librephotos/releases/tag/1.0.0
- https://www.vulncheck.com/advisories/librephotos-insecure-direct-object-reference-in-setphotosshared-endpoint
- https://github.com/LibrePhotos/librephotos/issues/1860



