WebSocket Server Vulnerability in GeoVision's Addon for GV-VMS and GV-Cloud
CVE-2026-57266

8.3HIGH

Key Information:

Vendor
CVE Published:
2 July 2026

What is CVE-2026-57266?

The GeoWebPlayer, an addon for GeoVision's GV-VMS and GV-Cloud software, has a vulnerability that exposes it to out-of-bounds access through its WebSocket server. This server accepts commands from localhost and processes an 'index' value to access various arrays. However, the lack of range validation on this index allows for potential exploitation, as attackers can send out-of-bound indices to access unintended memory areas. Proper safeguards and validation measures are essential to mitigate this risk and ensure the integrity of the system.

Affected Version(s)

GeoWebPlayer Windows V1.1.1.0

GeoWebPlayer Windows V1.1.3.0

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Philippe Laulheret of Cisco Talos
Kelly Patterson of Cisco Talos
Robert Sherwin of Cisco Talos
.