VYPR
Medium severity6.5NVD Advisory· Published Mar 26, 2026· Updated Jun 17, 2026

CVE-2026-33469

CVE-2026-33469

Description

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In version 0.17.0, an authenticated non-admin user can retrieve the full raw Frigate configuration through /api/config/raw. This exposes sensitive values that are intentionally redacted from /api/config, including camera credentials, go2rtc stream credentials, MQTT passwords, proxy secrets, and any other secrets stored in config.yml. This appears to be a broken access control issue introduced by the admin-by-default API refactor: /api/config/raw_paths is admin-only, but /api/config/raw is still accessible to any authenticated user. Version 0.17.1 contains a patch.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Frigate/Frigatellm-fuzzy2 versions
    <0.17.1+ 1 more
    • (no CPE)range: <0.17.1
    • cpe:2.3:a:frigate:frigate:0.17.0:*:*:*:*:*:*:*
  • Blakeblackshear/Frigatellm-fuzzy2 versions
    <0.17.1+ 1 more
    • (no CPE)range: <0.17.1
    • (no CPE)range: = 0.17.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.