MEDIUM 5.3 NVD
CVE-2026-102297
ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the FramesController index endpoint. Authenticated users with Events view permission
ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the FramesController index endpoint. Authenticated users with Events view permission can call the frames API to list frame records from monitors they are denied access to, disclosing event and frame metadata across monitor boundaries.
References
- https://github.com/ZoneMinder/zoneminder
- https://github.com/ZoneMinder/zoneminder/blob/1.38.3/web/api/app/Controller/FramesControll
- https://github.com/ZoneMinder/zoneminder/commit/aafe580b231bbeead12a110a957d85a26f7a23be
- https://github.com/ZoneMinder/zoneminder/commit/efe6c60d8798c60ab41b120dc034488388c47dda
- https://github.com/ZoneMinder/zoneminder/releases/tag/1.38.4
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-09-28 via NVD.
vulnfeed aggregates 13624 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.