External risk intelligence

motionEye Authentication Bypass Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-46488

motionEye is a web-based interface for video surveillance systems. These applications are commonly deployed to be accessible remotely for monitoring purposes, often exposing the web management interface to the network or the internet to facilitate remote camera viewing.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory describes a critical vulnerability in motionEye, a video surveillance interface. The issue allows an unauthenticated attacker with knowledge of a username and its hash to impersonate that user. This could lead to account lockouts, password changes, data exfiltration, or destruction.

  • Attackers can hijack user accounts remotely.
  • Secures video systems and sensitive data.
  • Verify if your video surveillance is impacted.

Attack Path

How an attacker could exploit the issue

An attacker could impersonate an administrator on motionEye by first gaining local shell access to the server to read the administrator's username and password hash. With this information, the attacker can then craft specific cookies to bypass authentication when interacting with the motionEye interface, potentially through a switch-user function, leading to account takeover and subsequent data manipulation or exfiltration.

  • Local shell access is required.
  • Crafted cookies authenticate as administrator.
  • Risk of account takeover and data compromise.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, an unauthenticated attacker who knows a target username and corresponding hash could impersonate that user within the motionEye interface. This could allow for account manipulation and unauthorized access to surveillance data.

  • Surveillance system access and control.
  • Attacker uses known username and hash.
  • Unauthorized account access and data manipulation.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and infrastructure teams are likely responsible for addressing this vulnerability in motionEye, as it affects the video surveillance interface. The first practical step involves identifying all instances of motionEye, confirming their reachability and criticality, locating the accountable owner, and then prioritizing remediation based on risk.

  • Identify motionEye instances and accountable owners.
  • Verify exposure and business criticality.
  • Plan remediation or risk reduction.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is motionEye and how is it used?

motionEye serves as a web-based management interface for the 'motion' software, a program designed to monitor and detect motion across video surveillance feeds. Users primarily interact with it to view live camera streams and configure system settings remotely through a browser, rather than interacting with the underlying motion engine directly.

What does CVE-2026-46488 mean for my security?

This vulnerability involves an Improper Authentication weakness. Because the software fails to validate session data on the server side, it trusts cookies provided by the client. An attacker can use a known username and its associated password hash to impersonate any user, including administrators, effectively bypassing the login process and gaining full control over the surveillance system.

How does an attacker trigger this authentication bypass?

An attacker must possess the victim's username and the corresponding password hash, which are stored in a file that is readable by local users by default. Once this information is obtained, the attacker can either manually set the required cookies in their browser or manipulate the application's user-switching flow to bypass authentication. Simply knowing the username alone is insufficient; the specific hash is required to complete the impersonation.

Is my motionEye instance at risk of this CVE?

According to Halo Surface Signal, motionEye interfaces are frequently deployed with network or internet accessibility to enable remote monitoring, which increases the likelihood of exposure. If your interface is reachable over the network, it is a potential target. Environments where the interface is strictly restricted to internal, private networks face lower risks compared to those exposed publicly.

How do I fix CVE-2026-46488 in my environment?

The most effective resolution is to update to version 0.44.0 or higher, which addresses the authentication validation flaw. Start by identifying all running instances of motionEye within your infrastructure and determining who is responsible for each deployment. Once you have an inventory, verify the reachability of these systems and prioritize the update process based on the criticality of the video surveillance data being managed.

References