Access Control Vulnerability in ZoneMinder CCTV Software
CVE-2026-54258

6.5MEDIUM

Key Information:

Vendor

Zoneminder

Vendor
CVE Published:
11 September 2026

What is CVE-2026-54258?

ZoneMinder, an open-source closed-circuit television application, has a security flaw that permits low-privileged authenticated users to access sensitive event media from restricted monitors. Although the standard user interface properly conceals these restricted monitors, vulnerability arises as direct access to event media can be manipulated using arbitrary event IDs. This lack of proper enforcement on event and monitor-level access control lists (ACLs) can lead to unauthorized exposure of private surveillance footage, sparking concerns over user privacy and data security.

Affected Version(s)

zoneminder < 1.36.39 < 1.36.39

zoneminder >= 1.37.0, < 1.38.4 < 1.37.0, 1.38.4

zoneminder >= 1.39.0, < 1.39.11 < 1.39.0, 1.39.11

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.