Local File Permissions Vulnerability in motionEye Surveillance Software
CVE-2026-32315
What is CVE-2026-32315?
The motionEye software, an online interface for motion detection video surveillance, has a vulnerability that allows sensitive configuration files, including /etc/motioneye/motion.conf, to be created with permissive 644 permissions. This exposes critical data, including the admin password hash, to any local user on the system. In addition to this, per-camera configuration files can also reveal specific camera credentials. Attackers may exploit the exposed SHA1 password hash offline to regain plaintext passwords, potentially using these with existing authentication weaknesses to create unauthorized API requests or leverage other vulnerabilities for privilege escalation—possibly gaining access to the Motion daemon user and thereby compromising the entire system. This issue has since been resolved in motionEye version 0.44.0.
Affected Version(s)
motioneye < 0.44.0
