Impact
ZoneMinder is a free, open‑source closed‑circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low‑privileged user with coarse Events=View and/or Snapshots=View permissions to directly fetch media for events belonging to monitors they are not allowed to access. The normal UI correctly hides the restricted monitor and its events, but the direct event media views accept an arbitrary eid and stream media from the event path without enforcing the event/monitor‑level ACL. This exposes private surveillance footage across monitor boundaries. The vulnerability is classified as CWE‑639, an Authorization Bypass Through User‑Controlled Key.
Affected Systems
ZoneMinder versions prior to 1.36.39, 1.38.4, and 1.39.11 are vulnerable. The flaw resides.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. Because the defect requires only an authenticated low‑privilege user with view permissions, the attack vector is local or any interface that allows the user to request the media URL. The EPSS score of less than 1% suggests a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, implying no widespread active exploitation at the time of this analysis.
OpenCVE Enrichment