PT-2026-96790 · Frigate · Frigate

CVE-2026-75607

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Frigate versions prior to 0.17.2
Description The WebSocket handler in frigate/comms/ws.py forwards message topics to the dispatcher without verifying the authenticated user's role. This occurs because the nginx authentication subrequest lacks role-aware authorization. Consequently, an authenticated user with viewer privileges can send admin-only topics, including restart, notifications/set, and settings for camera detection, recording, snapshot, audio, motion, and enablement. This can lead to unauthorized service restarts or the disabling of security monitoring functions. This issue requires authentication to be enabled and valid viewer credentials to be used.
Recommendations Update to version 0.17.2.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75607
GHSA-R5FM-H944-8CHQ

Affected Products

Frigate