Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-54258— Cross-monitor event media authorization bypass in direct event media endpoints

Quick assessment

Affected
ZoneMinder zoneminder
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

ZoneMinder 是一款免费的开源闭路电视软件应用。在 1.36.39、1.38.4 和 1.39.11 之前的版本中,拥有粗粒度“事件=查看”和/或“快照=查看”权限的低权限已认证用户,可以直接获取其无权访问的监控摄像头所属事件的媒体文件。正常用户界面会正确隐藏受限的监控摄像头及其事件,但直接的事件媒体视图接受任意的 (事件 ID),并从事件路径流式传输媒体文件,而未强制执行事件/监控摄像头级别的访问控制列表(ACL)。这导致不同监控摄像头之间的私人监控视频内容被暴露。该问题已在 1.36.39、1.38.4

CVSS 6.5 · Medium EPSS 0.03% · P8

Possible ATT&CK Techniques 1 AI

T1041 · Exfiltration Over C2 Channel
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54258

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cross-monitor event media authorization bypass in direct event media endpoints
Source: CVE Program / CVE List V5
Vulnerability Description
ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View` permissions to directly fetch media for events belonging to monitors they are not allowed to access. The normal UI correctly hides the restricted monitor and its events, but direct event media views accept an arbitrary `eid` and stream media from the event path without enforcing the event/monitor-level ACL. This exposes private surveillance footage across monitor boundaries. Versions 1.36.39, 1.38.4, and 1.39.11 fix the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ZoneMinder zoneminder < 1.36.39 -

II. Public POCs for CVE-2026-54258

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54258

登录查看更多情报信息。

Vendor Advisories for CVE-2026-54258 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-54258

No comments yet


Leave a comment