CyberRota Analysis
AI-GeneratedAn insecure direct object reference vulnerability in PhotoPrism allows any user with a valid preview token to access and download the original-resolution cover photos of albums they are not authorized to view. This could lead to unauthorized exposure of sensitive album information, impacting user privacy. Organizations using PhotoPrism should prioritize addressing this issue to protect user data and maintain trust.
CVE
CVE-2026-72540
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
Original NVD Description
Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.