PT-2026-51445 · Motioneye · Motioneye

CVE-2026-46488

·

Published

2026-06-22

·

Updated

2026-06-29

CVSS v4.0

9.1

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MotionEye (affected versions not specified)
Description An authentication bypass occurs because the application improperly trusts client-controlled cookies. The server accepts the cookies meye username and meye password hash as sufficient authentication material without validating them against a server-side session or enforcing proper authentication checks. An unauthenticated attacker can manually set or modify these cookies to impersonate any user if the target username and corresponding password hash are known. Furthermore, the admin account username and hash are stored in the /etc/motioneye/motion.conf file, which is globally readable by default on the local system, allowing local users with shell access to obtain these credentials and impersonate the administrator.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46488
GHSA-R3CW-C95M-WFH9
PYSEC-2026-428

Affected Products

Motioneye