CVE-2026-54258: Cross-monitor event media authorization bypass in direct event media endpoints
ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse Events=View and/or Snapshots=View permissions to directly fetch media for events belonging to monitors they are not allowed to access. The normal UI correctly hides the restricted monitor and its events, but direct event media views accept an arbitrary eid and stream media from the event path without enforcing the event/monitor-level ACL. This exposes private surveillance footage across monitor boundaries. Versions 1.36.39, 1.38.4, and 1.39.11 fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ZoneMinderto a version that resolves this vulnerability.Fixed in 1.36.39 - Upgrade
Upgrade
ZoneMinderto a version that resolves this vulnerability.Fixed in 1.38.4 - Upgrade
Upgrade
ZoneMinderto a version that resolves this vulnerability.Fixed in 1.39.11
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated low-privileged ZoneMinder user is exposed to this issue if they have coarse Events=View and/or Snapshots=View permissions. The user must be able to request direct event media endpoints and supply an event ID.
Does hiding monitors and events in the ZoneMinder UI prevent exploitation?
No. The normal UI hides monitors and events the user is not authorized to access, but the affected direct event media views accept an arbitrary eid without enforcing the event- or monitor-level ACL.
What data could be accessed?
An attacker can fetch media associated with events from monitors they are not permitted to access. This can expose private surveillance footage across monitor boundaries.
Which versions contain the fix?
The issue is fixed in ZoneMinder 1.36.39, 1.38.4, and 1.39.11. Versions prior to those releases are affected.