Incorrect Authorization in ZoneMinder FramesController for Monitors
CVE-2026-102297
5.3MEDIUM
What is CVE-2026-102297?
ZoneMinder versions prior to 1.38.4 are susceptible to incorrect authorization in the FramesController index endpoint. Authenticated users who have Events view permissions can exploit this vulnerability to retrieve frame records from monitors for which they are denied access. This could lead to unauthorized disclosure of event and frame metadata, compromising the security of sensitive monitor data across different user roles.
Affected Version(s)
zoneminder 0 < 1.38.4
zoneminder 1.38.4
