Description
ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View` permissions to directly fetch media for events belonging to monitors they are not allowed to access. The normal UI correctly hides the restricted monitor and its events, but direct event media views accept an arbitrary `eid` and stream media from the event path without enforcing the event/monitor-level ACL. This exposes private surveillance footage across monitor boundaries. Versions 1.36.39, 1.38.4, and 1.39.11 fix the issue.
Published: 2026-09-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality breach through media access bypass
Action: Immediate Patch
AI Analysis

Impact

ZoneMinder is a free, open‑source closed‑circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low‑privileged user with coarse Events=View and/or Snapshots=View permissions to directly fetch media for events belonging to monitors they are not allowed to access. The normal UI correctly hides the restricted monitor and its events, but the direct event media views accept an arbitrary eid and stream media from the event path without enforcing the event/monitor‑level ACL. This exposes private surveillance footage across monitor boundaries. The vulnerability is classified as CWE‑639, an Authorization Bypass Through User‑Controlled Key.

Affected Systems

ZoneMinder versions prior to 1.36.39, 1.38.4, and 1.39.11 are vulnerable. The flaw resides.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. Because the defect requires only an authenticated low‑privilege user with view permissions, the attack vector is local or any interface that allows the user to request the media URL. The EPSS score of less than 1% suggests a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, implying no widespread active exploitation at the time of this analysis.

Generated by OpenCVE AI on September 15, 2026 at 20:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ZoneMinder to version 1.36.39 or 1.38.4 or 1.39.11, or later, to apply the vendor fix.
  • Ensure that users with Events=View or Snapshots=View roles are only granted access to monitors they are authorized to monitor, removing direct media URLs for protected monitors now return a 403 or similar error and no longer stream media; test with a non‑privileged user’s credentials.
  • Enable detailed logging of direct media endpoint requests and periodically review audit logs for unauthorized access attempts, configuring alerts if suspicious activity is detected.

Generated by OpenCVE AI on September 15, 2026 at 20:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Zoneminder
Zoneminder zoneminder
Vendors & Products Zoneminder
Zoneminder zoneminder

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View` permissions to directly fetch media for events belonging to monitors they are not allowed to access. The normal UI correctly hides the restricted monitor and its events, but direct event media views accept an arbitrary `eid` and stream media from the event path without enforcing the event/monitor-level ACL. This exposes private surveillance footage across monitor boundaries. Versions 1.36.39, 1.38.4, and 1.39.11 fix the issue.
Title Cross-monitor event media authorization bypass in direct event media endpoints
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Zoneminder Zoneminder
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T16:50:32.195Z

Reserved: 2026-06-12T17:13:32.278Z

Link: CVE-2026-54258

cve-icon Vulnrichment

Updated: 2026-09-15T16:50:27.885Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T22:16:38.497

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54258

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:00:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key