CVE-2026-33124General(frigate / frigate)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Versions prior to 0.17.0-beta1 allow any authenticated user to change their own password without verifying the current password through the /users/{username}/password endpoint. Changing a password does not invalidate existing JWT tokens, and there is no validation of password strength. If an attacker obtains a valid session token (e.g., via accidentally exposed JWT, stolen cookie, XSS, compromised device, or sniffing over HTTP), they can change the victim’s password and gain permanent control of the account. Since password changes do not invalidate existing JWT tokens, session hijacks persist even after a password reset. Additionally, the lack of password strength validation exposes accounts to brute-force attacks. This issue has been resolved in version 0.17.0-beta1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • frigate

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-20); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
frigate

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-20: 1Mentions · 2026-03-22: 103-2003-22
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-201
General1
2026-03-221
Disclosure1
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33124 Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Versions prior to 0.17.0-beta1 allow any authenticated user to change t… https://www.cve.org/CVERecord?id=CVE-2026-33124

    Post summary

    The text announces CVE-2026-33124, indicating that versions before 0.17.0-beta1 allow any authenticated user to alter a setting, but does not provide PoC, exploit, or patch details.

    00000108
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33124 Frigate NVR Authentication Bypass Vulnerability Allows Persistent Account Takeover https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33124

    Post summary

    The text identifies CVE-2026-33124 as an authentication bypass vulnerability that could lead to account takeover, but provides no further technical details, evidence of exploitation, or patch information.

    0000041
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfrigatefrigate---

Explore more