Skip to content
June 12, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Vulnerability Report
  • CVE-2025-43856: OAuth2 Account Hijacking Flaw Found in Immich, a Popular Self-Hosted Photo Platform
  • Vulnerability Report

CVE-2025-43856: OAuth2 Account Hijacking Flaw Found in Immich, a Popular Self-Hosted Photo Platform

Do Son July 15, 2025 3 minutes read
0
Immich, Account Hijacking
Add as a preferred
source on Google

A critical vulnerability has been disclosed in Immich, a rapidly growing open-source project for self-hosted photo and video management, with over 70,000 stars on GitHub. Tracked as CVE-2025-43856 and rated CVSSv4 8.8 (High), the flaw allows attackers to hijack user accounts via a broken OAuth2 implementation.

β€œImmich is vulnerable to account hijacking through oauth2, because the state parameter is not being checked,” the project maintainers confirmed in their disclosure.

Immich is a self-hosted, privacy-focused media management tool that lets users backup, organize, and view personal photos and videos. With its intuitive web UI and seamless integration with mobile apps, it has become a go-to alternative to cloud-based services like Google Photosβ€”especially for privacy-conscious users.

OAuth2 is a widely adopted standard for authentication. It includes a crucial security mechanism called the state parameter, which acts like a CSRF token. It ensures that the response from the identity provider (e.g., Google) matches the original request made by the user’s browser.

Unfortunately, Immich failed to validate this parameter, meaning any state valueβ€”even state=gibberishβ€”would be accepted.

β€œThe state parameter is similar to a csrf token… before the user is logged in that parameter needs to be verified to make sure the login was actively initiated by the user in this browser session,” the report explained.

The vulnerability becomes especially dangerous due to the way Immich uses its /user-settings endpoint as the OAuth redirect URI. This page automatically links accounts when a user is already authenticated.

That means an attacker can craft a malicious URL that looks like a normal OAuth login flow, but instead:

  1. Logs the victim into the attacker’s OAuth account
  2. Links the victim’s Immich account to the attacker’s credentials
  3. Gives the attacker persistent access to the victim’s data

A simple hidden iframe or shortened link is all that’s needed to trigger the attack.

β€œIf someone has an Immich instance with a public oauth provider (like Google), an attacker can… embed a hidden iframe in a webpage or even just send the victim a forged oauth login url,” the advisory states.

The flaw affects all Immich instances using public OAuth2 providers like Google, GitHub, or any generic SSO setupβ€”whether self-hosted behind Cloudflare or accessible directly on the web.

In the worst-case scenario, an attacker could hijack an admin account, reconfigure the OAuth provider to their own, and lock everyone else out by disabling password login and terminating active sessions.

β€œIf the attacker manages to hijack an admin account this way, they could… start logging into arbitrary accounts and lock out the admin by disabling password login,” the report warns.

All versions prior to v1.132.0 are affected. The vulnerability is patched in Immich version 1.132.0.

Related Posts:

  • Amazon Redshift Alert: OAuth2 Vulnerability Exposes Data
  • CVE-2024-9014 (CVSS 9.9): pgAdmin’s Critical Vulnerability Puts User Data at Risk
  • Malicious Firefox Extensions Unmasked: Fake Games, VPNs, & Calendar Tools Hijack Traffic, Steal Crypto & OAuth Tokens
  • Phishing for Profits: Attackers Mine Crypto & Spam Through OAuth Apps
  • Russian Hackers Abuse Microsoft 365 OAuth in Sophisticated Phishing Attacks
Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. Critical OAuth2-Proxy Flaw (CVE-2025-54576, CVSS 9.1) Allows Authentication Bypass via Query Parameters
  2. Langflow Under Attacks: CVE-2025-3248 Exploited to Deliver Stealthy Flodrix Botnet
  3. Critical Meshtastic Flaw: Key Duplication Allows Message Decryption & Node Hijacking
  4. CVE-2025-54370: SSRF Vulnerability Discovered in PhpSpreadsheet Library
  5. CVE-2025-8077 (CVSS 9.8): CRITICAL Flaw in NeuVector Exposes Kubernetes Clusters to Full Takeover
Written by
@DdoS Β· Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Account Hijacking CSRF CVE-2025-43856 cybersecurity Immich OAuth2 open-source Photo Management Video Management Vulnerability

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚑

Get notified instantly when a Proof of Concept (PoC) exploit is published.

πŸ”

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

πŸ“Š

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

πŸ”΄ Live Critical Threats

  • CVE-2026-28742CVSS 9.8
    Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide...
  • CVE-2026-48558CVSS 10.0
    SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication...
  • CVE-2026-50091CVSS 9.1
    Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so)...
  • CVE-2026-50090CVSS 9.3
    The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect...
  • CVE-2026-50086CVSS 10.0
    The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's...
  • CVE-2026-50084CVSS 9.6
    The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token...
  • CVE-2026-50083CVSS 9.1
    The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which...
  • CVE-2026-6853CVSS 9.8
    Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe...
  • CVE-2026-54133CVSS 9.8
    jmespath.php allows users to use JMESPath, software for declaratively specifying how to...
  • CVE-2026-47210CVSS 9.8
    vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4,...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • GreatXML BitLocker Bypass: Public PoC Exploit Disclosed
  • Check Point VPN Vulnerability Exploited in the Wild with Ransomware Links
  • Weekly Threat Intelligence: June 1 to June 7, 2026
  • Cisco SD-WAN Vulnerability Exploited in the Wild with Root RCE Risks
  • Android Zero-Day Flaw Exploited in the Wild: June 2026 Patches Released
  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Β© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.