CVE-2026-102297
5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the FramesController index endpoint. Authenticated users with Events view permission can call the frames API to list frame records from monitors they are denied access to, disclosing event and frame metadata across monitor boundaries.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ZoneMinder | zoneminder | 0 < 1.38.4 | affected |
| ZoneMinder | zoneminder | 1.38.4 | unaffected |
Weaknesses
- CWE-863: Incorrect Authorization
References
- https://github.com/ZoneMinder/zoneminder/commit/aafe580b231bbeead12a110a957d85a26f7a23be
- https://github.com/ZoneMinder/zoneminder
- https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-mg2g-jmfc-3w8g
- https://github.com/ZoneMinder/zoneminder/commit/efe6c60d8798c60ab41b120dc034488388c47dda
- https://github.com/ZoneMinder/zoneminder/releases/tag/1.38.4
- https://github.com/ZoneMinder/zoneminder/blob/1.38.3/web/api/app/Controller/FramesController.php#L51
- https://www.vulncheck.com/advisories/zoneminder-before-1.38.4-incorrect-authorization-in-frames-api-index
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.