Incorrect authorization in ZoneMinder - #VU153361
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote user to rename a zone belonging to an explicitly denied camera.
The vulnerability exists due to incorrect authorization in the ZonesController::edit() API route when processing zone edit requests without checking access to the zone's owning monitor. A remote user can send a zone rename request targeting a zone on a denied monitor to rename a zone belonging to an explicitly denied camera.
Exploitation requires authentication and API access to be enabled, an enabled account with APIEnabled=1 and global Monitors=Edit permission, and an existing zone on the denied monitor. The edit operation does not restart the monitor.