Vulnerability Description
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In version 0.17.0, an authenticated non-admin user can retrieve the full raw Frigate configuration through `/api/config/raw`. This exposes sensitive values that are intentionally redacted from `/api/config`, including camera credentials, go2rtc stream credentials, MQTT passwords, proxy secrets, and any other secrets stored in `config.yml`. This appears to be a broken access control issue introduced by the admin-by-default API refactor: `/api/config/raw_paths` is admin-only, but `/api/config/raw` is still accessible to any authenticated user. Version 0.17.1 contains a patch.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Frigate | Frigate | 0.17.0 |
Related Weaknesses (CWE)
References
- https://github.com/blakeblackshear/frigate/security/advisories/GHSA-26g3-f8g8-9fExploitMitigationVendor Advisory
- https://github.com/blakeblackshear/frigate/security/advisories/GHSA-26g3-f8g8-9fExploitMitigationVendor Advisory
FAQ
What is CVE-2026-33469?
CVE-2026-33469 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In version 0.17.0, an authenticated non-admin user can retrieve the full raw Frigate configuration throug...
How severe is CVE-2026-33469?
CVE-2026-33469 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-33469?
Check the references section above for vendor advisories and patch information. Affected products include: Frigate Frigate.