CVE-2026-102297
Publication date 28 September 2026
Last updated 30 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the FramesController index endpoint. Authenticated users with Events view permission can call the frames API to list frame records from monitors they are denied access to, disclosing event and frame metadata across monitor boundaries.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| zoneminder | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
Severity score breakdown
CVSS version:
Base score
5.3 · Medium
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Base score
4.3 · Medium
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2026-102297
- https://github.com/ZoneMinder/zoneminder
- https://github.com/ZoneMinder/zoneminder/blob/1.38.3/web/api/app/Controller/FramesController.php#L51
- https://github.com/ZoneMinder/zoneminder/commit/aafe580b231bbeead12a110a957d85a26f7a23be
- https://github.com/ZoneMinder/zoneminder/commit/efe6c60d8798c60ab41b120dc034488388c47dda
- https://github.com/ZoneMinder/zoneminder/releases/tag/1.38.4
- https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-mg2g-jmfc-3w8g
- https://www.vulncheck.com/advisories/zoneminder-before-1.38.4-incorrect-authorization-in-frames-api-index