Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-46488— motionEye: Authentication possible via password hash

Quick assessment

Affected
motioneye-project motioneye
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

motionEye (mEye) 是一个名为“motion”的软件的在线管理界面,而 motion 是一款具有移动侦测功能的视频监控程序。在 0.44.0 版本之前,motionEye 接受由客户端控制的 和 Cookie 作为认证依据,且未进行服务器端的会话验证。 未认证的攻击者若知晓目标用户名及其对应的密码哈希值,可通过手动设置 Cookie,或通过“切换用户”认证流程提交空白凭据来触发加载这些 Cookie,从而让服务器将攻击者认证为该用户。 管理员用户名和密码哈希值存储在 文件中,该文件默认对系统所有用户可

CVSS 9.1 · Critical

Affected Version Matrix 1

VendorProduct Version RangeStatus
motioneye-project motioneye < 0.44.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-46488

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
motionEye: Authentication possible via password hash
Source: CVE Program / CVE List V5
Vulnerability Description
motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, motionEye accepts the client-controlled meye_username and meye_password_hash cookies as authentication material without server-side session validation. An unauthenticated attacker who knows a target username and corresponding hash can set the cookies manually or cause them to be loaded by submitting blank credentials through the switch-user authentication flow, after which the server authenticates the attacker as that user. The administrator username and password-hash value are stored in /etc/motioneye/motion.conf, which is globally readable by default, allowing a local shell user to obtain reusable administrator credential material. Successful impersonation can enable account lockout, password changes and persistence, data enumeration, data destruction, and data exfiltration. This issue is fixed in version 0.44.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
明文存储口令
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
motioneye-project motioneye < 0.44.0 -

II. Public POCs for CVE-2026-46488

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-46488

登录查看更多情报信息。

Patches & Fixes for CVE-2026-46488 (1)

Vendor Advisories for CVE-2026-46488 (1)

Vendor Pages for CVE-2026-46488 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-46488

No comments yet


Leave a comment