Authorization Flaw in Genetec Security Center's Media Gateway API
CVE-2026-65422
6.5MEDIUM
What is CVE-2026-65422?
An authorization flaw has been identified in the Media Gateway API of Genetec Security Center, which may enable users without playback privileges to mistakenly generate video thumbnails. This issue could compromise content confidentiality and integrity, leading to unauthorized access and potential misuse of sensitive video data. The vendor has addressed this flaw in the latest software updates, reinforcing user access controls.
Affected Version(s)
Genetec Security Center Windows <5.12.2.22 < 5.12.2.22
Genetec Security Center Windows <5.13.3.9 < 5.13.3.9
Genetec Security Center Windows <5.14.1.2 < 5.14.1.2
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Sirak Tsegaye (Rok$i), Yeabsira Tesfaye (Xenon), Information Network Security Administration (INSA)
