WebSocket Handler Vulnerability in Frigate Network Video Recorder
CVE-2026-75607
8.1HIGH
What is CVE-2026-75607?
Frigate, an open-source network video recorder, has a security issue in its WebSocket handler which improperly forwards messages from authenticated users without checking their roles. This flaw allows any authenticated viewer to access and execute admin-level commands, including restarting the service and managing critical camera functions such as motion detection and audio settings. The vulnerability exploits the lack of role-aware authorization provided by the nginx authentication subrequest. The issue has been resolved in version 0.17.2, so users are advised to update promptly to mitigate risks.
Affected Version(s)
frigate < 0.17.2
