Broken Access Control Vulnerability in Frigate NVR by Blake Blackshear
CVE-2026-33469
6.5MEDIUM
What is CVE-2026-33469?
Frigate, a network video recorder developed by Blake Blackshear, suffers from a broken access control vulnerability in version 0.17.0. An authenticated non-admin user can gain access to the full raw Frigate configuration through the endpoint /api/config/raw, unintentionally revealing sensitive information including camera credentials, MQTT passwords, and other secrets derived from the config.yml file. While access to the /api/config/raw_paths endpoint is restricted to admin users only, the /api/config/raw endpoint remains accessible to all authenticated users, leading to significant security risks. A patch has been implemented in version 0.17.1 to mitigate this issue.
Affected Version(s)
frigate = 0.17.0
