Access Control Vulnerability in HikCentral Professional by Hikvision
CVE-2026-1749

6.8MEDIUM

Key Information:

Vendor

Hikvision

Vendor
CVE Published:
9 May 2026

What is CVE-2026-1749?

An access control vulnerability in HikCentral Professional can potentially allow an unauthenticated user to gain unauthorized admin permissions. This flaw poses significant security risks as it enables attackers to manipulate sensitive system settings and access confidential data without authentication. It is crucial for users of HikCentral Professional to apply necessary security updates and monitor their systems for any suspicious activity.

Affected Version(s)

HikCentral Professional V2.4.0~V3.0.1

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ayoub ELMOKHTAR from the Offensive Security Team (Noon)
.