Access Control Vulnerability in ZoneMinder CCTV Software
CVE-2026-54258
6.5MEDIUM
What is CVE-2026-54258?
ZoneMinder, an open-source closed-circuit television application, has a security flaw that permits low-privileged authenticated users to access sensitive event media from restricted monitors. Although the standard user interface properly conceals these restricted monitors, vulnerability arises as direct access to event media can be manipulated using arbitrary event IDs. This lack of proper enforcement on event and monitor-level access control lists (ACLs) can lead to unauthorized exposure of private surveillance footage, sparking concerns over user privacy and data security.
Affected Version(s)
zoneminder < 1.36.39 < 1.36.39
zoneminder >= 1.37.0, < 1.38.4 < 1.37.0, 1.38.4
zoneminder >= 1.39.0, < 1.39.11 < 1.39.0, 1.39.11
