No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 12 Sep 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zoneminder
Zoneminder zoneminder |
|
| Vendors & Products |
Zoneminder
Zoneminder zoneminder |
Fri, 11 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View` permissions to directly fetch media for events belonging to monitors they are not allowed to access. The normal UI correctly hides the restricted monitor and its events, but direct event media views accept an arbitrary `eid` and stream media from the event path without enforcing the event/monitor-level ACL. This exposes private surveillance footage across monitor boundaries. Versions 1.36.39, 1.38.4, and 1.39.11 fix the issue. | |
| Title | Cross-monitor event media authorization bypass in direct event media endpoints | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T16:50:32.195Z
Reserved: 2026-06-12T17:13:32.278Z
Link: CVE-2026-54258
Updated: 2026-09-15T16:50:27.885Z
Status : Received
Published: 2026-09-11T22:16:38.497
Modified: 2026-09-15T17:17:19.980
Link: CVE-2026-54258
No data.
OpenCVE Enrichment
Updated: 2026-09-15T21:00:17Z