PT-2026-96790 · Frigate · Frigate
CVE-2026-75607
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Frigate versions prior to 0.17.2
Description
The WebSocket handler in
frigate/comms/ws.py forwards message topics to the dispatcher without verifying the authenticated user's role. This occurs because the nginx authentication subrequest lacks role-aware authorization. Consequently, an authenticated user with viewer privileges can send admin-only topics, including restart, notifications/set, and settings for camera detection, recording, snapshot, audio, motion, and enablement. This can lead to unauthorized service restarts or the disabling of security monitoring functions. This issue requires authentication to be enabled and valid viewer credentials to be used.Recommendations
Update to version 0.17.2.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Frigate