{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/photoview/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:photoview:photoview:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-96271"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Photoview (\u003c= 2.4.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-application","graphql"],"_cs_type":"advisory","_cs_vendors":["Photoview"],"content_html":"\u003cp\u003ePhotoview versions 2.4.0 and earlier are affected by an authorization bypass vulnerability located in the shareAlbum GraphQL mutation. The vulnerability permits an authenticated user to perform a GraphQL request specifying an arbitrary album ID, even if that album does not belong to the requesting user. The application fails to validate ownership of the target album before processing the request, resulting in the generation of a functional share token. An attacker can leverage this to create persistent public access links for private albums, exposing sensitive photo collections and nested sub-albums to unauthorized parties without the owner's knowledge. This issue poses a significant risk to data privacy for users deploying Photoview in multi-user or shared environments.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the complete unauthorized exposure of private media collections. Because the generated share tokens provide persistent access, an attacker retains control over the shared link, potentially leading to widespread data exfiltration if the albums contain sensitive personal content. The vulnerability affects all users running vulnerable instances of Photoview, impacting personal or organizational storage instances.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade to the latest version of Photoview beyond 2.4.0 to resolve the authorization logic flaw.\u003c/li\u003e\n\u003cli\u003eAudit current album share settings within the application to identify and revoke any suspicious or unauthorized tokens.\u003c/li\u003e\n\u003cli\u003eRestrict access to the GraphQL endpoint for unauthorized users if immediate patching is not possible.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-23T06:41:22Z","date_published":"2026-09-23T06:41:22Z","id":"https://feed.craftedsignal.io/briefs/2026-09-photoview-auth-bypass/","summary":"Photoview versions through 2.4.0 contain an authorization bypass in the shareAlbum GraphQL mutation, allowing authenticated users to generate unauthorized share tokens for albums owned by others.","title":"Authorization Bypass Vulnerability in Photoview shareAlbum Mutation","url":"https://feed.craftedsignal.io/briefs/2026-09-photoview-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Photoview","version":"https://jsonfeed.org/version/1.1"}