Authorization bypass through user-controlled key in ZoneMinder - #VU153362
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote user to disclose recorded JPEG frames from monitors they are denied access to.
The vulnerability exists due to authorization bypass through a user-controlled monitor ID in the native nph-zms CGI when serving recorded event media without checking access to the event's actual monitor. A remote user can supply an allowed monitor ID with an event ID belonging to a denied monitor, or omit the monitor parameter, to disclose recorded JPEG frames from monitors they are denied access to.
Exploitation requires knowledge of an event ID. The demonstrated viewer had Stream=View and Events=View permissions.