Executive brief
motionEye, a popular web interface for managing video surveillance cameras, contains a security flaw that allows attackers to bypass the login screen. By providing a specific user ID and a password hash in the browser's cookies, an attacker can gain full access to the system without knowing the actual password. This could allow unauthorized individuals to view private camera feeds, change system settings, or delete recorded footage.
Technical details
An authentication bypass vulnerability exists in motionEye versions prior to 0.44.0 due to improper trust in client-controlled cookies. The application accepts the `meye_username` and `meye_password_hash` cookies as sufficient proof of identity without verifying them against a server-side session state. An attacker who knows or can obtain a user's password hash (which is stored in a globally readable configuration file on some systems) can manually set these cookies to impersonate any user, including the administrator. This allows for full account takeover and unauthorized access to the camera management interface. The issue is addressed in version 0.44.0.
Affected products
- motioneye-project motionEye < 0.44.0
Timeline
- 2026-06-20: disclosed
- 2026-06-22: advisory
References
- https://api.github.com/users/FireByteApplications
- https://github.com/FireByteApplications
- https://api.github.com/users/FireByteApplications/gists%7B/gist_id%7D
- https://api.github.com/users/FireByteApplications/repos
- https://avatars.githubusercontent.com/u/53253862?v=4
- https://api.github.com/users/FireByteApplications/events%7B/privacy%7D