PT-2026-28485 · Frigate · Frigate
Bg0D-Glitch
·
Published
2026-03-26
·
Updated
2026-03-26
·
CVE-2026-33470
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Frigate version 0.17.0
Description
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. A low-privilege authenticated user restricted to one camera can access snapshots from other cameras. This is possible due to authorization problems in two API endpoints:
/api/timeline returns timeline entries for cameras outside the caller's allowed camera set, and /api/events/{event id}/snapshot-clean.webp does not validate event.camera after looking up the event, despite declaring Depends(require camera access). This allows a restricted user to enumerate event IDs from unauthorized cameras and then fetch clean snapshots for those events using the event id variable.Recommendations
Update to version 0.17.1 or later.
Exploit
Fix
Incorrect Authorization
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Frigate