CVE-2026-31978Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

motionEye (mEye) is an online interface for motion software, which is a video surveillance program with motion detection. Versions prior to 0.44.0 are vulnerable to path traversal in the picture and movie API endpoints, suhc as /picture/{id}/preview/{filename}. Neither the API handlers, nor the mediafiles.py functions such as get_media_preview() check for .. sequences in the filename parameter, except for get_media_content(). This allows an authenticated user with normal (non-admin) privileges to read arbitrary files from the filesystem as the motionEye process user, such as: /etc/passwd, /etc/shadow, motionEye config files containing password hashes and plaintext passwords, SSH keys, and other cameras' surveillance footage. This issue has been fixed in version 0.44.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-23: 3Technical Details · 2026-06-23: 306-23
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 motionEye, Partial Authentication Bypass / Path Traversal, #CVE-2026-31978, #CVE-2026-32315, #CVE-2026-46488 (Critical) -DC-Jun2026-600 https://dailycve.com/motioneye-partial-authentication-bypass-path-traversal-cve-2026-31978-cve-2026-32315-cve-2026-46488-critical-dc-jun2026-600/

    Post summary

    The post announces three new critical CVEs for motionEye, highlighting partial authentication bypass and path traversal flaws, and directs readers to a DailyCVE article for details.

    0000034
    216 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 motionEye, Multi-Stage Chain RCE, #CVE-2025-60787 / #CVE-2026-31978 (Critical) -DC-Jun2026-597 https://dailycve.com/motioneye-multi-stage-chain-rce-cve-2025-60787-cve-2026-31978-critical-dc-jun2026-597/

    Post summary

    The text announces two critical multi‑stage chain RCE vulnerabilities (CVE‑2025‑60787 and CVE‑2026‑31978) in motionEye, providing a link to a detailed disclosure.

    0000049
    216 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 motionEye, Absolute Path Traversal, #CVE-2026-31978 (Moderate) -DC-Jun2026-598 https://dailycve.com/motioneye-absolute-path-traversal-cve-2026-31978-moderate-dc-jun2026-598/

    Post summary

    The post announces CVE‑2026‑31978, an absolute path traversal vulnerability in motionEye with moderate severity, and provides a link to a dailycve page for further details.

    0000033
    216 followersView on X

Explore more