CVE-2026-23896 | immich-app immich up to 2.4.x Update Endpoint privileges management (GHSA-237r-x578-h5mv / EUVD-2026-4957)
A vulnerability was found in immich-app immich up to 2.4.x. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the component Update Endpoint. This manipulation causes improper privilege management.
This vulnerability appears as CVE-2026-23896. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.