Skip to content
September 28, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Vulnerability Report
  • CVE-2025-43856: OAuth2 Account Hijacking Flaw Found in Immich, a Popular Self-Hosted Photo Platform
  • Vulnerability Report

CVE-2025-43856: OAuth2 Account Hijacking Flaw Found in Immich, a Popular Self-Hosted Photo Platform

Do Son July 15, 2025 3 minutes read
0
Immich, Account Hijacking
Add Daily CyberSecurity as a preferred source on Google

A critical vulnerability has been disclosed in Immich, a rapidly growing open-source project for self-hosted photo and video management, with over 70,000 stars on GitHub. Tracked as CVE-2025-43856 and rated CVSSv4 8.8 (High), the flaw allows attackers to hijack user accounts via a broken OAuth2 implementation.

Running Infra, AppSec, and SOC teams? Tag CVE alerts by team automatically.

Try Team free for 14 days →

“Immich is vulnerable to account hijacking through oauth2, because the state parameter is not being checked,” the project maintainers confirmed in their disclosure.

Immich is a self-hosted, privacy-focused media management tool that lets users backup, organize, and view personal photos and videos. With its intuitive web UI and seamless integration with mobile apps, it has become a go-to alternative to cloud-based services like Google Photos—especially for privacy-conscious users.

OAuth2 is a widely adopted standard for authentication. It includes a crucial security mechanism called the state parameter, which acts like a CSRF token. It ensures that the response from the identity provider (e.g., Google) matches the original request made by the user’s browser.

Unfortunately, Immich failed to validate this parameter, meaning any state value—even state=gibberish—would be accepted.

“The state parameter is similar to a csrf token… before the user is logged in that parameter needs to be verified to make sure the login was actively initiated by the user in this browser session,” the report explained.

The vulnerability becomes especially dangerous due to the way Immich uses its /user-settings endpoint as the OAuth redirect URI. This page automatically links accounts when a user is already authenticated.

That means an attacker can craft a malicious URL that looks like a normal OAuth login flow, but instead:

  1. Logs the victim into the attacker’s OAuth account
  2. Links the victim’s Immich account to the attacker’s credentials
  3. Gives the attacker persistent access to the victim’s data

A simple hidden iframe or shortened link is all that’s needed to trigger the attack.

“If someone has an Immich instance with a public oauth provider (like Google), an attacker can… embed a hidden iframe in a webpage or even just send the victim a forged oauth login url,” the advisory states.

The flaw affects all Immich instances using public OAuth2 providers like Google, GitHub, or any generic SSO setup—whether self-hosted behind Cloudflare or accessible directly on the web.

In the worst-case scenario, an attacker could hijack an admin account, reconfigure the OAuth provider to their own, and lock everyone else out by disabling password login and terminating active sessions.

“If the attacker manages to hijack an admin account this way, they could… start logging into arbitrary accounts and lock out the admin by disabling password login,” the report warns.

All versions prior to v1.132.0 are affected. The vulnerability is patched in Immich version 1.132.0.

Related Posts:

  • Amazon Redshift Alert: OAuth2 Vulnerability Exposes Data
  • CVE-2024-9014 (CVSS 9.9): pgAdmin’s Critical Vulnerability Puts User Data at Risk
  • Malicious Firefox Extensions Unmasked: Fake Games, VPNs, & Calendar Tools Hijack Traffic, Steal Crypto & OAuth Tokens
  • Phishing for Profits: Attackers Mine Crypto & Spam Through OAuth Apps
  • Russian Hackers Abuse Microsoft 365 OAuth in Sophisticated Phishing Attacks

Related coverage

  • Root Access Granted: Four Critical RCE Flaws Patched in SolarWinds Serv-U
  • CVE-2026-61511: vBulletin Preauth RCE with Public PoC Disclosed
  • Four undici Vulnerabilities Affect a Package With 133M Weekly Downloads
  • CVE-2026-49488: Arbitrary File Read Flaw in Apache OpenMeetings Exposes Server Credentials
  • EchoLeak: First AI Zero-Click Vulnerability Leaks Data from Microsoft 365 Copilot
  • CVE-2026-32475: Elementor Pro RCE Exploited in the Wild
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Account Hijacking CSRF CVE-2025-43856 cybersecurity Immich OAuth2 open-source Photo Management Video Management Vulnerability

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-48842CVSS 8.1
    Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via...
    Admin intel📅 Updated: Sep 23, 2026
  • CVE-2026-87902
    Unauthenticated path traversal in page-template resolution leading to conditional RCE An unauthenticated attacker can make get_page_template() page-template resolution...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 23, 2026
  • CVE-2026-94127CVSS 9.8
    When a BIG-IP APM access policy and an OAuth profile is configured on a virtual server, specific malicious...
    Admin intelCISA KEV📅 Added to KEV: Sep 22, 2026📅 Updated: Sep 22, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-101894CVSS 9.1
    The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies...
    📅 Updated: Sep 28, 2026
  • CVE-2026-101891CVSS 9.3
    An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker...
    📅 Updated: Sep 28, 2026
  • CVE-2026-86102CVSS 9.3
    An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access...
    📅 Updated: Sep 28, 2026
  • CVE-2026-100721CVSS 9.5
    vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with...
    📅 Updated: Sep 28, 2026
  • CVE-2026-101081CVSS 9.4
    A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the...
    📅 Updated: Sep 28, 2026
  • CVE-2026-100684CVSS 9.2
    Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate,...
    📅 Updated: Sep 28, 2026
  • CVE-2026-63374CVSS 9.3
    AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or...
    📅 Updated: Sep 28, 2026
  • CVE-2026-101075CVSS 10.0
    A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of...
    📅 Updated: Sep 28, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.