User Account Deletion in Frigate Network Video Recorder
CVE-2026-33125

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
20 March 2026

What is CVE-2026-33125?

Frigate is a network video recorder (NVR) designed for real-time local object detection with IP cameras. In versions up to 0.16.2, a vulnerability allows users with the viewer role to delete both admin and lower-privileged user accounts. This can lead to denial of service (DoS) and potential compromise of data integrity. The issue has been addressed in version 0.16.3, which mitigates the risk associated with improper access controls.

Affected Version(s)

frigate < 0.16.3

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.