Access Control Vulnerability in HikCentral Professional by Hikvision
CVE-2026-1749
6.8MEDIUM
What is CVE-2026-1749?
An access control vulnerability in HikCentral Professional can potentially allow an unauthenticated user to gain unauthorized admin permissions. This flaw poses significant security risks as it enables attackers to manipulate sensitive system settings and access confidential data without authentication. It is crucial for users of HikCentral Professional to apply necessary security updates and monitor their systems for any suspicious activity.
Affected Version(s)
HikCentral Professional V2.4.0~V3.0.1
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ayoub ELMOKHTAR from the Offensive Security Team (Noon)
