CVE-2026-54258
ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View` permissions to directly fetch media for events belonging to monitors they are not allowed to access. The normal UI correctly hides the restricted monitor and its events, but direct event media views accept an arbitrary `eid` and stream media from the event path without enforcing the event/monitor-level ACL. This exposes private surveillance footage across monitor boundaries. Versions 1.36.39, 1.38.4, and 1.39.11 fix the issue.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- CWE
- CWE-639
- Published
- 2026-09-11
- Last modified
- 2026-09-11
Affected products
- ZoneMinder zoneminder
- ZoneMinder zoneminder
- ZoneMinder zoneminder
Weakness type
Related vulnerabilities
- CVE-2026-90552 — WWBN AVideo Missing Authorization via Playlists_schedules list.json.php
- CVE-2026-90542 — WWBN AVideo Missing Authorization via remindMe.json.php
- CVE-2026-90534 — Flowise before 3.1.4 Cross-Workspace Credential IDOR via node-load-method
- CVE-2026-49464 — NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak
- CVE-2026-81916 — Incorrect Authorization in the Concrete CMS Express Entries Dashboard below version 9.5.3 Allows Entry Creation in an Unauthorized Object
- CVE-2026-81915 — In Concrete CMS below 9.5.3, Page Type update omits object-level authorization
- CVE-2026-62134 — WordPress Starter Templates plugin <= 4.7.5 - Insecure Direct Object References (IDOR) vulnerability
- CVE-2026-62113 — WordPress Slim SEO plugin <= 4.10.0 - Insecure Direct Object References (IDOR) vulnerability