Threat Advisory

MotionEye Vulnerability Allows Authentication Bypass

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-46488 with a CVSS score of 9.1 is a critical authentication bypass vulnerability in the motionEye package, specifically affecting versions prior to 0.44.0, which arises due to improper trust in client-controlled cookies, allowing attackers to impersonate arbitrary users without knowledge of the plaintext password by setting or modifying cookies named `meye_password_hash` and `meye_username` prior to login, which can be done using standard browser tools or dynamically loaded by submitting blank credentials, and an attacker can exploit this vulnerability by having access to a username and corresponding hash, or by obtaining the admin username and hash from the globally readable `/etc /motioneye /motion .conf` file, gaining the capability to authenticate as the specified user, bypassing the intended authentication flow, and potentially leading to business impacts such as account lockouts, attacker persistence, enumeration of data, destruction of data, and exfiltration of data, particularly in multi-user environments where local access to the system can be used to retrieve a valid hash and values, with prerequisites for exploitation including knowledge of the target username and corresponding hash, or local access to the system to obtain the admin username and hash from the configuration file.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-46488 with a CVSS score of 9.1 is a critical authentication bypass vulnerability in the motionEye package, specifically affecting versions prior to 0.44.0, which arises due to improper trust in client-controlled cookies, allowing attackers to impersonate arbitrary users without knowledge of the plaintext password by setting or modifying cookies named `meye_password_hash` and `meye_username` prior to login, which can be done using standard browser tools or dynamically loaded by submitting blank credentials, and an attacker can exploit this vulnerability by having access to a username and corresponding hash, or by obtaining the admin username and hash from the globally readable `/etc /motioneye /motion .conf` file, gaining the capability to authenticate as the specified user, bypassing the intended authentication flow, and potentially leading to business impacts such as account lockouts, attacker persistence, enumeration of data, destruction of data, and exfiltration of data, particularly in multi-user environments where local access to the system can be used to retrieve a valid hash and values, with prerequisites for exploitation including knowledge of the target username and corresponding hash, or local access to the system to obtain the admin username and hash from the configuration file.[emaillocker id="1283"]

RECOMMENDATION:

We recommend you to update motionEye to version 0.44.0.

REFERENCES:

The following reports contain further technical details:
https://github.com/advisories/GHSA-r3cw-c95m-wfh9

[/emaillocker]
crossmenu