Executive brief
motionEye is a web-based interface for managing video surveillance cameras. A security flaw allows unauthorized individuals to remotely trigger camera actions such as taking snapshots, starting or stopping recordings, and controlling physical hardware like alarms or camera movement. This could lead to a breach of physical security or unauthorized monitoring of a facility.
Technical details
The ActionHandler.post() method in motioneye/handlers/action.py lacks the @BaseHandler.auth() decorator, resulting in a missing authorization vulnerability (CWE-862). An unauthenticated attacker can send a POST request to the /action/ endpoint to trigger camera functions including snapshots, recording, and PTZ controls. If custom action scripts are configured, this can also lead to the execution of predefined shell scripts. The vulnerability is confirmed in version 0.43.1 and addressed in version 0.44.0.
Affected products
- motioneye-project motioneye < 0.44.0
Timeline
- 2026-06-20: disclosed
- 2026-06-23: advisory: GitHub Advisory published
References
- https://api.github.com/users/alanturing881
- https://github.com/alanturing881
- https://api.github.com/users/alanturing881/gists%7B/gist_id%7D
- https://api.github.com/users/alanturing881/repos
- https://avatars.githubusercontent.com/u/286391906?v=4
- https://api.github.com/users/alanturing881/events%7B/privacy%7D