Path Traversal Vulnerability in motionEye Video Surveillance Software
CVE-2026-31978

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
24 June 2026

What is CVE-2026-31978?

The motionEye software, an online interface for motion detection in video surveillance, contains a path traversal vulnerability in versions prior to 0.44.0. This flaw allows authenticated users with non-admin privileges to exploit the API, gaining access to arbitrary files on the server, including sensitive information like passwords, SSH keys, and video footage. Specifically, the issue originates from insufficient validation of the filename parameter in API endpoints such as /picture/{id}/preview/{filename}. The vulnerability has been addressed in version 0.44.0, enhancing the security of users' data.

Affected Version(s)

motioneye < 0.44.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.