CVE-2026-33125

Severity CVSS v4.0:
Pending analysis
Type:
CWE-285 Improper Authorization
Publication date:
20/03/2026
Last modified:
20/03/2026

Description

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In versions 0.16.2 and below, users with the viewer role can delete admin and low-privileged user accounts. Exploitation can lead to DoS and affect data integrity. This issue has been patched in version 0.16.3.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:frigate:frigate:*:*:*:*:*:*:*:* 0.16.3 (excluding)