Authentication Bypass in Frigate Network Video Recorder
CVE-2026-75608
7.7HIGH
What is CVE-2026-75608?
Frigate, an open-source network video recorder, has a significant flaw in its API security. Prior to version 0.18.0, the /api/go2rtc/api endpoint was accessible to authenticated viewers without requiring an administrator role for GET requests. This oversight allows those users to access sensitive information such as stream URLs, internal addresses, application logs, and configuration paths, which could potentially include camera credentials. Although non-GET requests are restricted, the exposure of internal data can lead to serious security implications. The vulnerability has been addressed in version 0.18.0.
Affected Version(s)
frigate < 0.18.0
