PT-2026-51445 · Motioneye · Motioneye
CVE-2026-46488
·
Published
2026-06-22
·
Updated
2026-06-29
CVSS v4.0
9.1
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MotionEye (affected versions not specified)
Description
An authentication bypass occurs because the application improperly trusts client-controlled cookies. The server accepts the cookies
meye username and meye password hash as sufficient authentication material without validating them against a server-side session or enforcing proper authentication checks. An unauthenticated attacker can manually set or modify these cookies to impersonate any user if the target username and corresponding password hash are known. Furthermore, the admin account username and hash are stored in the /etc/motioneye/motion.conf file, which is globally readable by default on the local system, allowing local users with shell access to obtain these credentials and impersonate the administrator.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Motioneye