PT-2026-28485 · Frigate · Frigate

Bg0D-Glitch

·

Publicado

2026-03-26

·

Atualizado

2026-03-26

·

CVE-2026-33470

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Frigate version 0.17.0
Description Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. A low-privilege authenticated user restricted to one camera can access snapshots from other cameras. This is possible due to authorization problems in two API endpoints: /api/timeline returns timeline entries for cameras outside the caller's allowed camera set, and /api/events/{event id}/snapshot-clean.webp does not validate event.camera after looking up the event, despite declaring Depends(require camera access). This allows a restricted user to enumerate event IDs from unauthorized cameras and then fetch clean snapshots for those events using the event id variable.
Recommendations Update to version 0.17.1 or later.

Exploit

Correção

Incorrect Authorization

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33470
GHSA-M2MG-PJ9P-2R7G

Produtos afetados

Frigate