VDB
Sign up
HIGH7.1

PYSEC-2026-2483

Frigte has broken access control viewer user can delete admin and other users account

Quick fix

PYSEC-2026-2483 — frigate: upgrade to the fixed version with the command below.

pip install --upgrade 'frigate>=0.16.3'

Details

### Summary Users with the viewer role can delete admin and other users account. It this leads to denial of service and affects data integrity.

### Details Endpoint `DELETE /api/users/admin` is enable to anonymous user.

<img width="436" height="100" alt="obraz" src="https://github.com/user-attachments/assets/817f9c47-7bd9-4247-a2f1-0f40778ab229" />

### PoC I deleted admin user on `demo.frigate.video`:

<img width="1091" height="222" alt="obraz" src="https://github.com/user-attachments/assets/34f50a13-3bb7-4aa8-99fa-bd815b3dc915" />

### Impact It this leads to denial of service and affects data integrity.

### Recommended Fixes Restrict access to the endpoint to authenticated admin users only: Add `dependencies=[Depends(require_role(["admin"]))])` to this endpoint.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/frigate
Introduced in: 0Fixed in: 0.16.3
Fixpip install --upgrade 'frigate>=0.16.3'

References