Description
ZoneMinder versions 1.37.0 before 1.38.0 contain a path traversal vulnerability in the files view that allows authenticated users to read arbitrary files. The path parameter is not properly validated before being passed to output_file, enabling attackers with Events view permission to access sensitive files like configuration files containing database credentials.
Published: 2026-09-28
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Read arbitrary files (confidentiality compromise)
Action: Immediate Patch
AI Analysis

Impact

ZoneMinder versions 1.37.0 up to 1.37.x contain a path traversal vulnerability in the files view. This flaw is a Path Traversal (CWE-22) vulnerability. The path parameter is not validated before being passed to output_file, allowing authenticated users with Events view permission to read arbitrary files on the host. Attackers could therefore access configuration files that contain database credentials or other sensitive data, compromising confidentiality.

Affected Systems

Vulnerable versions include any 1.37.x release before the 1.38.0 update, affecting the ZoneMinder surveillance software deployed on network cameras and media servers. The affected product is the ZoneMinder package from the ZoneMinder vendor. The vulnerability affects all installations that enable the files view functionality, regardless of other configuration settings.

Risk and Exploitability

The CVSS score is 7.1, indicating a high-impact vulnerability, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Attackers need only authenticated access with Events view permission, which is typically granted to users who can see recorded footage. By manipulating the path argument, they can traverse directories and read files outside the intended directory, making exploitation straightforward for users who already have legitimate access. The risk is especially high in environments where ZoneMinder reads configuration files that include database passwords, as the vulnerability enables credential theft.

Generated by OpenCVE AI on September 28, 2026 at 23:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ZoneMinder to version 1.38.0 or later
  • Limit Events view permissions to trusted users or remove them entirely
  • Enforce strict file system permissions so that the ZoneMinder process cannot read sensitive files outside its intended directories

Generated by OpenCVE AI on September 28, 2026 at 23:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description ZoneMinder versions 1.37.0 before 1.38.0 contain a path traversal vulnerability in the files view that allows authenticated users to read arbitrary files. The path parameter is not properly validated before being passed to output_file, enabling attackers with Events view permission to access sensitive files like configuration files containing database credentials.
Title ZoneMinder 1.37.x Path Traversal via files view
First Time appeared Zoneminder
Zoneminder zoneminder
Weaknesses CWE-22
CPEs cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:*
Vendors & Products Zoneminder
Zoneminder zoneminder
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Zoneminder Zoneminder
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-28T22:28:06.645Z

Reserved: 2026-09-28T21:24:45.481Z

Link: CVE-2024-58386

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T22:17:29.893

Modified: 2026-09-28T22:17:29.893

Link: CVE-2024-58386

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T01:00:11Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')