CVE-2026-33125

7.1

blakeblackshear · Frigate

An improper authorization flaw in Frigate allows authenticated users with the viewer role to delete other user accounts, leading to potential denial of service and data integrity compromise.

Executive summary

A critical authorization vulnerability in Frigate allows low-privileged users to delete administrative accounts, posing a significant risk to system availability and security integrity.

Vulnerability

This vulnerability, categorized as Improper Authorization (CWE-285), allows an authenticated user with limited viewer privileges to perform unauthorized administrative actions, specifically the deletion of user accounts. The attack vector is network-based and requires a low-privileged login to trigger the flaw.

Business impact

The ability for a viewer-level user to delete administrative accounts constitutes a severe security breakdown. Successful exploitation results in a denial of service for legitimate administrators and compromises the integrity of the user management system, which may lead to unauthorized access or complete loss of control over the NVR deployment. With a CVSS score of 7.1, this represents a high-severity risk that demands immediate attention to prevent operational disruption.

Remediation

Immediate Action: Update Frigate to version 0.16.3 or later immediately to apply the necessary authorization checks.

Proactive Monitoring: Review audit logs for unexpected account management activity or unauthorized attempts by low-privileged users to access administrative endpoints.

Compensating Controls: Restrict access to the Frigate web interface to trusted networks via VPN or firewall rules and monitor for abnormal API requests targeting user management functions.

Exploitation status

Public Exploit Available: No confirmed public exploit (weaponized or otherwise) is available based on current data.

Analyst recommendation

Given the potential for complete loss of administrative control, organizations running Frigate must prioritize updating to version 0.16.3. Organizations unable to patch immediately should restrict access to the NVR interface to prevent low-privileged users from interacting with the vulnerable management functions.

More blakeblackshear CVEs

Sources