Authentication Bypass in Frigate Network Video Recorder
CVE-2026-75608

7.7HIGH

Key Information:

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-75608?

Frigate, an open-source network video recorder, has a significant flaw in its API security. Prior to version 0.18.0, the /api/go2rtc/api endpoint was accessible to authenticated viewers without requiring an administrator role for GET requests. This oversight allows those users to access sensitive information such as stream URLs, internal addresses, application logs, and configuration paths, which could potentially include camera credentials. Although non-GET requests are restricted, the exposure of internal data can lead to serious security implications. The vulnerability has been addressed in version 0.18.0.

Affected Version(s)

frigate < 0.18.0

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.