Nginx · Nginx · CVE-2026-54652
**Name of the Vulnerable Software and Affected Versions**
Frigate version 0.17.1
**Description**
An issue exists where the 'GET /api/logs/{service}' endpoint allows any authenticated user, including those with the viewer role, to download Frigate and nginx logs. This exposure includes auto-generated admin passwords and camera credentials contained within request query strings, which can lead to privilege escalation from a viewer to an administrator.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.