CVE-2026-33469
Frigate
- Published
- 26 March 2026
- Last modified
- 17 June 2026
- CVSS
- 6.5 v3.1
- Severity
- medium
- EPSS
- 0.2% (16th pct)
- CISA KEV
- Not listed
- NVD status
- Analyzed
- Weaknesses
- CWE-863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Description
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In version 0.17.0, an authenticated non-admin user can retrieve the full raw Frigate configuration through `/api/config/raw`. This exposes sensitive values that are intentionally redacted from `/api/config`, including camera credentials, go2rtc stream credentials, MQTT passwords, proxy secrets, and any other secrets stored in `config.yml`. This appears to be a broken access control issue introduced by the admin-by-default API refactor: `/api/config/raw_paths` is admin-only, but `/api/config/raw` is still accessible to any authenticated user. Version 0.17.1 contains a patch.
Exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalogue as of 2026.09.04. That is an absence of confirmed public exploitation, not evidence that exploitation has not occurred. EPSS models a 0.2% probability of exploitation activity in the next 30 days.
Affected products
| Product | Vendor | Type | Versions named |
|---|---|---|---|
| Frigate | Frigate | unknown | 0.13.0, 0.17.0, < 0.16.3, < 0.16.4 +2 |
References
Vendor advisory and patch
- https://github.com/blakeblackshear/frigate/security/advisories/GHSA-26g3-f8g8-9ffh
- https://github.com/blakeblackshear/frigate/security/advisories/GHSA-26g3-f8g8-9ffh
Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.