Authorization Flaw in Genetec Security Center's Media Gateway API
CVE-2026-65422

6.5MEDIUM

Key Information:

Vendor
CVE Published:
24 September 2026

What is CVE-2026-65422?

An authorization flaw has been identified in the Media Gateway API of Genetec Security Center, which may enable users without playback privileges to mistakenly generate video thumbnails. This issue could compromise content confidentiality and integrity, leading to unauthorized access and potential misuse of sensitive video data. The vendor has addressed this flaw in the latest software updates, reinforcing user access controls.

Affected Version(s)

Genetec Security Center Windows <5.12.2.22 < 5.12.2.22

Genetec Security Center Windows <5.13.3.9 < 5.13.3.9

Genetec Security Center Windows <5.14.1.2 < 5.14.1.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sirak Tsegaye (Rok$i), Yeabsira Tesfaye (Xenon), Information Network Security Administration (INSA)
.