Local File Permissions Vulnerability in motionEye Surveillance Software
CVE-2026-32315

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
24 June 2026

What is CVE-2026-32315?

The motionEye software, an online interface for motion detection video surveillance, has a vulnerability that allows sensitive configuration files, including /etc/motioneye/motion.conf, to be created with permissive 644 permissions. This exposes critical data, including the admin password hash, to any local user on the system. In addition to this, per-camera configuration files can also reveal specific camera credentials. Attackers may exploit the exposed SHA1 password hash offline to regain plaintext passwords, potentially using these with existing authentication weaknesses to create unauthorized API requests or leverage other vulnerabilities for privilege escalation—possibly gaining access to the Motion daemon user and thereby compromising the entire system. This issue has since been resolved in motionEye version 0.44.0.

Affected Version(s)

motioneye < 0.44.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.