CVE-2026-54258: Cross-monitor event media authorization bypass in direct event media endpoints

Published Sep 11, 2026
·
Updated

ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse Events=View and/or Snapshots=View permissions to directly fetch media for events belonging to monitors they are not allowed to access. The normal UI correctly hides the restricted monitor and its events, but direct event media views accept an arbitrary eid and stream media from the event path without enforcing the event/monitor-level ACL. This exposes private surveillance footage across monitor boundaries. Versions 1.36.39, 1.38.4, and 1.39.11 fix the issue.

Affected Software

1 affected component
ZoneMinder Zoneminder>0<=1.36.38, >0<=1.38.3, >0<=1.39.10

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ZoneMinder to a version that resolves this vulnerability.

    Fixed in 1.36.39
  2. Upgrade

    Upgrade ZoneMinder to a version that resolves this vulnerability.

    Fixed in 1.38.4
  3. Upgrade

    Upgrade ZoneMinder to a version that resolves this vulnerability.

    Fixed in 1.39.11

Event History

Sep 11, 2026
CVE Published
via MITRE·09:31 PM
Data Sourced
via MITRE·09:31 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated low-privileged ZoneMinder user is exposed to this issue if they have coarse Events=View and/or Snapshots=View permissions. The user must be able to request direct event media endpoints and supply an event ID.

2

Does hiding monitors and events in the ZoneMinder UI prevent exploitation?

No. The normal UI hides monitors and events the user is not authorized to access, but the affected direct event media views accept an arbitrary eid without enforcing the event- or monitor-level ACL.

3

What data could be accessed?

An attacker can fetch media associated with events from monitors they are not permitted to access. This can expose private surveillance footage across monitor boundaries.

4

Which versions contain the fix?

The issue is fixed in ZoneMinder 1.36.39, 1.38.4, and 1.39.11. Versions prior to those releases are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203