CVE-2026-54258
Received Received - Intake

Unauthorized Media Access in ZoneMinder

Vulnerability report for CVE-2026-54258, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: GitHub, Inc.

Description

ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View` permissions to directly fetch media for events belonging to monitors they are not allowed to access. The normal UI correctly hides the restricted monitor and its events, but direct event media views accept an arbitrary `eid` and stream media from the event path without enforcing the event/monitor-level ACL. This exposes private surveillance footage across monitor boundaries. Versions 1.36.39, 1.38.4, and 1.39.11 fix the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-12
AI Q&A
2026-09-12
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
zoneminder zoneminder to 1.36.39 (exc)
zoneminder zoneminder 1.36.39
zoneminder zoneminder 1.38.4
zoneminder zoneminder 1.39.11

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in ZoneMinder allows an authenticated low-privileged user with limited permissions to bypass access controls and view media from events they are not authorized to access. The UI hides restricted monitors, but direct media requests using an event ID can stream footage from any event path without enforcing access restrictions.

Detection Guidance

Check ZoneMinder versions with 'zmupdate.pl --version' or 'dpkg -l | grep zoneminder'. Monitor for unauthorized access to event media paths or unusual eid parameters in logs.

Impact Analysis

This vulnerability exposes private surveillance footage to unauthorized users. Attackers with low-level access could view sensitive video feeds from other monitors, leading to privacy breaches and potential misuse of captured data.

Compliance Impact

This vulnerability could violate privacy regulations like GDPR and HIPAA by exposing sensitive surveillance data to unauthorized individuals. Organizations using ZoneMinder may face compliance violations, legal penalties, and reputational damage due to unauthorized data exposure.

Mitigation Strategies

Upgrade ZoneMinder to versions 1.36.39, 1.38.4, or 1.39.11 or later immediately. Review and restrict user permissions to prevent unauthorized access to events and snapshots.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54258. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart