---
id: CVE-2026-102297
title: >-
  ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the
  FramesController index endpoint
summary: >-
  ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the
  FramesController index endpoint. Authenticated users with Events view
  permission can call the frames API to list frame records from monitors they
  are denied a…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-863
vendor: ZoneMinder
product: zoneminder
affected:
  - zoneminder < 1.38.4
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T22:17:32.407'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102297'
references:
  - url: 'https://github.com/ZoneMinder/zoneminder'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ZoneMinder/zoneminder/blob/1.38.3/web/api/app/Controller/FramesController.php#L51
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ZoneMinder/zoneminder/commit/aafe580b231bbeead12a110a957d85a26f7a23be
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ZoneMinder/zoneminder/commit/efe6c60d8798c60ab41b120dc034488388c47dda
    label: disclosure@vulncheck.com
  - url: 'https://github.com/ZoneMinder/zoneminder/releases/tag/1.38.4'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-mg2g-jmfc-3w8g
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/zoneminder-before-1.38.4-incorrect-authorization-in-frames-api-index
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T22:22:13.611Z'
---

## Overview

ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the FramesController index endpoint. Authenticated users with Events view permission can call the frames API to list frame records from monitors they are denied access to, disclosing event and frame metadata across monitor boundaries.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
