5.3
CVE-2026-102297
- EPSS 0.22%
- Veröffentlicht 28.09.2026 22:17:32
- Zuletzt bearbeitet 30.09.2026 17:23:08
- Erkennungen
ZoneMinder before 1.38.4 Incorrect Authorization in frames API index
ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the FramesController index endpoint. Authenticated users with Events view permission can call the frames API to list frame records from monitors they are denied access to, disclosing event and frame metadata across monitor boundaries.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerZoneMinder
≫
Produkt
zoneminder
Default Statusunaffected
Version
0
Version <
1.38.4
Status
affected
Version
1.38.4
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.116 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 5.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| disclosure@vulncheck.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://github.com/ZoneMinder/zoneminder
https://github.com/ZoneMinder/zoneminder/releases/tag/1.38.4
https://github.com/ZoneMinder/zoneminder/blob/1.38.3/web/api/app/Controller/FramesController.php#L51
https://github.com/ZoneMinder/zoneminder/commit/aafe580b231bbeead12a110a957d85a26f7a23be
https://github.com/ZoneMinder/zoneminder/commit/efe6c60d8798c60ab41b120dc034488388c47dda
https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-mg2g-jmfc-3w8g
https://www.vulncheck.com/advisories/zoneminder-before-1.38.4-incorrect-authorization-in-frames-api-index