Authorization bypass through user-controlled key in ZoneMinder - #VU153362

 

Authorization bypass through user-controlled key in ZoneMinder - #VU153362

Published: October 6, 2026


Vulnerability identifier: #VU153362
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose recorded JPEG frames from monitors they are denied access to.

The vulnerability exists due to authorization bypass through a user-controlled monitor ID in the native nph-zms CGI when serving recorded event media without checking access to the event's actual monitor. A remote user can supply an allowed monitor ID with an event ID belonging to a denied monitor, or omit the monitor parameter, to disclose recorded JPEG frames from monitors they are denied access to.

Exploitation requires knowledge of an event ID. The demonstrated viewer had Stream=View and Events=View permissions.


Affected software

ZoneMinder

Remediation

Install security update from vendor's website.

ZoneMinder - addressed in versions 1.38.5, 1.38.6

External References

Related Security Bulletins