Incorrect authorization in ZoneMinder - #VU153360
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote user to create unauthorized Frame and EventData database records for events belonging to explicitly denied monitors.
nThe vulnerability exists due to incorrect authorization in the FramesController::add() and EventDataController::add() handlers when processing API record-creation requests. A remote user can submit POST requests to /api/frames/add.json and /api/event_data/add.json using an Events=View account to create unauthorized Frame and EventData database records for events belonging to explicitly denied monitors.
nExploitation requires the API to be enabled and the account to have APIEnabled=1.