Authentication Bypass Vulnerability in motionEye Surveillance Software
CVE-2026-46488
What is CVE-2026-46488?
motionEye, an online interface for the motion video surveillance program, contains a serious authentication bypass vulnerability. Prior to version 0.44.0, the software improperly validates client-controlled cookies used for authentication. An unauthenticated attacker, possessing knowledge of a username and its associated password hash, can manually set these cookies or exploit the login flow with blank credentials. This flaw allows the attacker to impersonate the target user without legitimate access. Once authenticated, the attacker can achieve unauthorized actions such as account lockout, changing passwords, data enumeration, destruction, and exfiltration. This vulnerability arises from the global readability of administrator credentials stored in /etc/motioneye/motion.conf, allowing local users to exploit this weakness easily. The issue has been addressed in version 0.44.0.
Affected Version(s)
motioneye < 0.44.0
