Authentication Bypass Vulnerability in motionEye Surveillance Software
CVE-2026-46488

9.1CRITICAL

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-46488?

motionEye, an online interface for the motion video surveillance program, contains a serious authentication bypass vulnerability. Prior to version 0.44.0, the software improperly validates client-controlled cookies used for authentication. An unauthenticated attacker, possessing knowledge of a username and its associated password hash, can manually set these cookies or exploit the login flow with blank credentials. This flaw allows the attacker to impersonate the target user without legitimate access. Once authenticated, the attacker can achieve unauthorized actions such as account lockout, changing passwords, data enumeration, destruction, and exfiltration. This vulnerability arises from the global readability of administrator credentials stored in /etc/motioneye/motion.conf, allowing local users to exploit this weakness easily. The issue has been addressed in version 0.44.0.

Affected Version(s)

motioneye < 0.44.0

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.