Home

Description

Kenik Camera management Panel is vulnerable to Path Traversal vulnerability. An unauthenticated attacker can send GET request with arbitrary file path and read corresponding files located on the server. The issue was fixed in version 2026-04-23 of the KG-5260xxxx-IL-(G)2 cameras. Rest of the products were fixed in version 2025-04-21.

PUBLISHED Reserved 2026-05-04 | Published 2026-05-25 | Updated 2026-05-26 | Assigner CERT-PL




HIGH: 8.3CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

Problem types

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

Default status
unaffected

Any version before 2025-04-21
affected

Default status
unaffected

Any version before 2025-04-21
affected

Default status
unaffected

Any version before 2025-04-21
affected

Default status
unaffected

Any version before 2025-04-21
affected

Default status
unaffected

Any version before 2025-04-21
affected

Default status
unaffected

Any version before 2025-04-21
affected

Default status
unaffected

Any version before 2025-04-21
affected

Default status
unaffected

Any version before 2026-04-23
affected

Credits

Łukasz Bawolski (Exea Data Center) finder

References

cert.pl/posts/2026/05/CVE-2026-7766 third-party-advisory

cve.org (CVE-2026-7766)

nvd.nist.gov (CVE-2026-7766)

Download JSON