CVE-2026-55863 Overview
motionEye (mEye) is a web-based frontend for the motion video surveillance daemon. A missing authorization flaw [CWE-862] in versions prior to 0.44.0 exposes the ActionHandler.post() method in motioneye/handlers/action.py without the BaseHandler.auth() decorator. Unauthenticated remote attackers can send requests to /action/<camera_id>/<action> and trigger snapshot, record_start, and record_stop actions. When administrators have configured action scripts, the same endpoint can invoke pan-tilt-zoom (PTZ) controls, alarm actions, lighting actions, and other predefined commands. Configured remote motionEye cameras can also be abused to issue server-side requests to the remote camera service. The issue is fixed in version 0.44.0.
Critical Impact
Unauthenticated remote attackers can invoke administrator-defined action scripts on affected motionEye deployments and trigger server-side requests to remote camera services.
Affected Products
- motionEye versions prior to 0.44.0
- Deployments exposing the motionEye web interface on trusted or untrusted networks
- motionEye instances with configured action scripts or remote motionEye camera integrations
Discovery Timeline
- 2026-09-15 - CVE CVE-2026-55863 published to NVD
- 2026-09-16 - Last updated in NVD database
Technical Details for CVE-2026-55863
Vulnerability Analysis
The defect is a missing authorization control on a state-changing HTTP endpoint. The ActionHandler.post() method handles requests to /action/<camera_id>/<action> but does not apply the BaseHandler.auth() decorator used elsewhere in the project. As a result, the endpoint accepts requests without validating a session or credentials.
An attacker with network reach to the motionEye interface can trigger built-in actions such as snapshot capture, record_start, and record_stop. Where administrators have configured action scripts, the endpoint dispatches those scripts, extending the impact to PTZ movement, alarm triggering, and lighting control. Because motionEye supports remote camera configurations, the endpoint can also cause the server to issue outbound requests to the remote camera service, creating a limited server-side request vector.
Root Cause
The root cause is a broken access control pattern [CWE-862]: a handler method that should require authentication was defined without the BaseHandler.auth() decorator. The authorization gate present on peer endpoints was omitted, and requests to the action route reach handler logic without any identity check.
Attack Vector
Exploitation is network-based and requires no authentication or user interaction. An attacker sends a crafted HTTP POST to /action/<camera_id>/<action> on the motionEye service. Valid values for <action> include snapshot, record_start, record_stop, and any administrator-defined action script names.
// Patch context from upstream fix commit
+* text=auto
+*.sh text eol=lf
+linux_init text eol=lf
+po2json text eol=lf
+*.py text eol=lf
// Source: https://github.com/motioneye-project/motioneye/commit/0d5cb9c238a87447dae29812e5bf2ccf323cf3dc
// The upstream fix replaces URL signature authentication with sessions and HMAC peer authentication (PR #3332).
Detection Methods for CVE-2026-55863
Indicators of Compromise
- Unauthenticated HTTP POST requests to /action/<camera_id>/<action> in motionEye access logs.
- Unexpected invocations of snapshot, record_start, or record_stop on cameras outside of scheduled or user-driven activity.
- Execution of administrator-configured action scripts, such as PTZ, alarm, or lighting commands, with no correlated authenticated session.
- Outbound HTTP requests from the motionEye host to remote camera endpoints without a corresponding administrator action.
Detection Strategies
- Alert on requests to the /action/ URL path where the request lacks a valid authenticated session cookie or HMAC header.
- Correlate action-script process executions on the motionEye host with authenticated web session events; flag executions without a matching session.
- Baseline normal recording and PTZ activity and alert on frequency or timing anomalies.
Monitoring Recommendations
- Forward motionEye web server and application logs to a centralized logging platform for retention and correlation.
- Monitor process creation on the motionEye host for spawns of configured action scripts and correlate with the invoking HTTP request.
- Track outbound network connections from the motionEye service, particularly to camera and internal network destinations.
How to Mitigate CVE-2026-55863
Immediate Actions Required
- Upgrade motionEye to version 0.44.0 or later, which adds the missing authentication decorator and introduces session and HMAC peer authentication.
- Restrict network access to the motionEye web interface using firewall rules, VPN, or reverse proxy authentication until the upgrade is applied.
- Review configured action scripts and remove or disable any that perform sensitive operations while a vulnerable version remains reachable.
Patch Information
The fix is delivered in motionEye 0.44.0. The upstream change replaces URL signature authentication with sessions and HMAC peer authentication, and applies the BaseHandler.auth() decorator to ActionHandler.post(). See the GitHub Security Advisory GHSA-j67x-q29f-qcvv, the upstream fix commit, the pull request discussion, and the 0.44.0 release notes.
Workarounds
- Place the motionEye interface behind a reverse proxy that enforces authentication on all paths, including /action/.
- Bind the motionEye service to localhost or a management VLAN and reach it through an authenticated tunnel.
- Temporarily remove administrator-configured action scripts to reduce impact until the upgrade to 0.44.0 is deployed.
# Example nginx location block requiring HTTP Basic auth in front of motionEye
location /action/ {
auth_basic "motionEye restricted";
auth_basic_user_file /etc/nginx/.htpasswd;
proxy_pass http://127.0.0.1:8765;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.