ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the FramesController index endpoint. Authenticated users with Events view permission can call the frames API to list frame records from monitors they are denied access to, disclosing event and frame metadata across monitor boundaries.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 28 Sep 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the FramesController index endpoint. Authenticated users with Events view permission can call the frames API to list frame records from monitors they are denied access to, disclosing event and frame metadata across monitor boundaries. | |
| Title | ZoneMinder before 1.38.4 Incorrect Authorization in frames API index | |
| First Time appeared |
Zoneminder
Zoneminder zoneminder |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zoneminder
Zoneminder zoneminder |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-28T22:28:09.404Z
Reserved: 2026-09-28T21:24:45.106Z
Link: CVE-2026-102297
No data.
Status : Received
Published: 2026-09-28T22:17:32.407
Modified: 2026-09-28T22:17:32.407
Link: CVE-2026-102297
No data.
OpenCVE Enrichment
No data.
Weaknesses