CVE-2026-33125: high-severity vulnerability in blakeblackshear frigate
Frigate Broken Access Control: Users assigned the viewer role can delete admin and other low-privileged accounts
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.1epss 0.4%
exploitation probability
0.4%top 71% of all CVEs
observed exploitation
nono source reports it
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In versions 0.16.2 and below, users with the viewer role can delete admin and low-privileged user accounts. Exploitation can lead to DoS and affect data integrity. This issue has been patched in version 0.16.3.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Affected products
blakeblackshear · frigateRelated CVEs — blakeblackshear frigate
In the same product, most dangerous first.
CVE-2026-25643CRITICALFrigate Affected by Authenticated Remote Command Execution (RCE) and Container EscapeEPSS 4.2%CVE-2023-45671MEDIUMFrigate reflected XSS through `/<camera_name>` API endpointsEPSS 1.4%CVE-2023-45672HIGHFrigate unsafe deserialization in `load_config_with_no_duplicates` of `frigate/util/builtin.py`EPSS 1.4%CVE-2024-32874MEDIUMIn Frigate, Malicious Long Unicode filenames may cause a Multiple Application-level Denial of ServiceEPSS 0.8%CVE-2026-75607HIGHFrigate: WebSocket Missing Authorization — Viewer Can Execute Admin-Only OperationsEPSS 0.6%CVE-2026-33124HIGHFrigate has insecure password change functionalityEPSS 0.4%