CVE-2026-46488Critical· 9.1▾ AbyssalPoC availablemotionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, motionEye accepts the client-controlled meye_username and meye_password_hash c…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 50.1 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 17.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
— → 9.1
Last analysed / modified upstream
0.3%
Exploit / PoC code exists
motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, motionEye accepts the client-controlled meye_username and meye_password_hash cookies as authentication material without server-side session validation. An unauthenticated attacker who knows a target username and corresponding hash can set the cookies manually or cause them to be loaded by submitting blank credentials through the switch-user authentication flow, after which the server authenticates the attacker as that user. The administrator username and password-hash value are stored in /etc/motioneye/motion.conf, which is globally readable by default, allowing a local shell user to obtain reusable administrator credential material. Successful impersonation can enable account lockout, password changes and persistence, data enumeration, data destruction, and data exfiltration. This issue is fixed in version 0.44.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
motioneye < 0.44.0Patched in:
motioneye 0.44.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55863Medium· 5.3motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection
CVE-2021-44255High· 7.2Unrestricted Upload of File with Dangerous Type in motionEye
CVE-2025-60787High· 7.2motionEye vulnerable to RCE via unsanitized motion config parameter
CVE-2025-47782HighmotionEye vulnerable to RCE in add_camera Function Due to unsafe command execution
CVE-2026-31978Medium· 6.5motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint
CVE-2026-32315Medium· 5.5motionEye's World-Readable Configuration File Exposes Admin Password Hash