SCA: security update for motioneye (GHSA-r3cw-c95m-wfh9)

critical Tenable Self-Hosted Container Security Plugin ID 443786

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- motionEye (mEye) is an online interface for a piece of software called "motion," which is a video
surveillance program with motion detection. Prior to 0.44.0, motionEye accepts the client-controlled
meye_username and meye_password_hash cookies as authentication material without server-side session
validation. An unauthenticated attacker who knows a target username and corresponding hash can set the
cookies manually or cause them to be loaded by submitting blank credentials through the switch-user
authentication flow, after which the server authenticates the attacker as that user. The administrator
username and password-hash value are stored in /etc/motioneye/motion.conf, which is globally readable by
default, allowing a local shell user to obtain reusable administrator credential material. Successful
impersonation can enable account lockout, password changes and persistence, data enumeration, data
destruction, and data exfiltration. This issue is fixed in version 0.44.0. (CVE-2026-46488)

Solution

Update the motioneye library and its related packages to version 0.44.0 or later.

See Also

https://github.com/advisories/GHSA-r3cw-c95m-wfh9

Plugin Details

Severity: Critical

ID: 443786

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 6/23/2026

Updated: 9/16/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.41

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 4.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2026-46488

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.1

Threat Score: 6.9

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 6/22/2026

Vulnerability Publication Date: 6/22/2026

Reference Information

CVE: CVE-2026-46488