---
id: CVE-2026-54258
title: >-
  ZoneMinder is a free, open source closed-circuit television software
  application
summary: >-
  ZoneMinder is a free, open source closed-circuit television software
  application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an
  authenticated low-privileged user with coarse `Events=View` and/or
  `Snapshots=View` permissions to …
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-639
vendor: ZoneMinder
product: zoneminder
affected:
  - zoneminder < 1.36.39
  - 'zoneminder >= 1.37.0, < 1.38.4'
  - 'zoneminder >= 1.39.0, < 1.39.11'
published: '2026-09-11'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T17:17:19.980'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-54258'
references:
  - url: >-
      https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-vj5r-pc2v-gfwv
    label: security-advisories@github.com
  - url: >-
      https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-vj5r-pc2v-gfwv
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T16:49:55.325622Z'
epss: 0.0034
epssPercentile: 0.24738
ingestedAt: '2026-09-14T11:11:19.876Z'
---

## Overview

ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View` permissions to directly fetch media for events belonging to monitors they are not allowed to access. The normal UI correctly hides the restricted monitor and its events, but direct event media views accept an arbitrary `eid` and stream media from the event path without enforcing the event/monitor-level ACL. This exposes private surveillance footage across monitor boundaries. Versions 1.36.39, 1.38.4, and 1.39.11 fix the issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
