CVE-2026-46488Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-06-23); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-23: 2Mentions · 2026-09-15: 1Patch / Workaround · 2026-06-23: 1Technical Details · 2026-06-23: 206-2309-15
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse3 posts
  • Aretiq.AI@AretiqAI

    ARETIQ Daily Vulnerability Bulletin — September 15, 2026 🔴 CRITICAL: CVE-2026-59971 (designcomputer/mysql_mcp_server) AAS 13.8 🔴 CRITICAL: CVE-2026-46488 (motioneye-project/motioneye) AAS 13.3 — exploited ITW (X/Twitter signals) 31 vulnerabilities — CRITICAL: 2, HIGH: 29 Full bulletin: https://aretiq.ai/bulletins/2026-09-15/

    0002063
    231 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 motionEye, Partial Authentication Bypass / Path Traversal, #CVE-2026-31978, #CVE-2026-32315, #CVE-2026-46488 (Critical) -DC-Jun2026-600 https://dailycve.com/motioneye-partial-authentication-bypass-path-traversal-cve-2026-31978-cve-2026-32315-cve-2026-46488-critical-dc-jun2026-600/

    Post summary

    The tweet announces newly identified critical CVEs for motionEye involving partial authentication bypass and path traversal, but no proof of concept, exploit, or patches are referenced.

    0000034
    216 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - motionEye Authentication Bypass via Password-Hash Cookie (CVE-2026-46488) motionEye trusts client-controlled cookies (meye_username and meye_password_hash) as sufficient authentication material, with no server-side session validation. An attacker who knows a target's username and password-hash value can set or modify these cookies - manually via browser dev tools, or by submitting blank credentials to load them - and impersonate that user, bypassing the login flow entirely. Worse, the admin username and hash live in /etc/motioneye/motion.conf, which is globally readable by default, so any local user with shell access can grab a valid admin hash and take over the admin account. Impact includes account lockout, persistence via password change, and data theft or destruction. 👉Upgrade to motionEye 0.44.0.

    Post summary

    The post discloses a credential bypass flaw in motionEye, provides technical details, and urges users to upgrade to version 0.44.0.

    0000070
    226 followersView on X

Explore more