OVERVIEW: CVE-2026-39957 is a SQL operator-precedence bug in Lychee, an open-source photo-management application, affecting versions prior to 7.5.4. The vulnerability exists in the SharingController::listAll() function, where a malformed orWhereNotNull clause bypasses ownership filters, allowing authenticated users with upload permissions to enumerate user-group-based sharing permissions across the entire instance. SEVERITY: The vulnerability carries a CVSS 3.1 score of 4.3 (Medium severity) with a network-based attack vector requiring low complexity and user authentication. The impact is limited to confidentiality, exposing sensitive information about album sharing configurations and potentially revealing private albums belonging to other users, while maintaining integrity and availability. The FAUCET Risk Score of 38.0 indicates moderate concern within the broader threat landscape. EXPLOITATION STATUS: There is no evidence of active exploitation in the wild, as indicated by the absence of KEV designation and inactive status on public exploit lists. The EPSS score of 0.00033 suggests minimal probability of exploitation attempts. While the vulnerability requires authentication and specific permissions to exploit, organizations running Lychee versions prior to 7.5.4 should apply patches promptly to prevent potential information disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.5.4CPE matchmatch criteria | cpe:2.3:a:lycheeorg:lychee:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.