CVE-2026-57945 Details
Description
PhotoPrism before 260601-a7d098548 contains a broken access control vulnerability that allows authenticated non-admin users to modify other users' profile information by sending requests to arbitrary user endpoints. Attackers can exploit the missing session-to-user identifier validation in the PUT users API endpoint to overwrite another user's profile details without authorization.
A broken access control vulnerability has been identified in PhotoPrism versions prior to 260601-a7d098548. This vulnerability allows authenticated non-admin users to modify the profile information of other users. The issue arises from a lack of proper validation of session-to-user identifiers in the PUT users API endpoint, enabling unauthorized users to overwrite another user's profile details by sending requests to arbitrary user endpoints.
Users can update to PhotoPrism version 260601-a7d098548 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 29, 2026CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/photoprism/photoprism/issues/5619 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://github.com/photoprism/photoprism/releases/tag/260601-a7d098548 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/photoprism-unauthorized-user-profile-modification-via-put-api-v1-users-uid-endpoint | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| PhotoPrism | < 260601-a7d098548 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jun 29, 2026 | New CVE Received | [email protected] |
Volerion