PT-2026-28485 · Frigate · Frigate

Bg0D-Glitch

·

Published

2026-03-26

·

Updated

2026-03-26

·

CVE-2026-33470

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Frigate version 0.17.0
Description Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. A low-privilege authenticated user restricted to one camera can access snapshots from other cameras. This is possible due to authorization problems in two API endpoints: /api/timeline returns timeline entries for cameras outside the caller's allowed camera set, and /api/events/{event id}/snapshot-clean.webp does not validate event.camera after looking up the event, despite declaring Depends(require camera access). This allows a restricted user to enumerate event IDs from unauthorized cameras and then fetch clean snapshots for those events using the event id variable.
Recommendations Update to version 0.17.1 or later.

Exploit

Fix

Incorrect Authorization

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-33470
GHSA-M2MG-PJ9P-2R7G

Affected Products

Frigate