Authorization Flaws in State-Changing Interfaces for Digital Watchdog Products
CVE-2026-66887

9.4CRITICAL

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-66887?

The identified vulnerability in Digital Watchdog products occurs due to inadequate authorization checks on state-changing CGI operations. This oversight may allow unauthorized users to manipulate system states without proper session validation, potentially leading to significant security risks. Users should be aware that this vulnerability poses a threat as it could be exploited to gain unauthorized control over the affected devices.

Affected Version(s)

VA1G4 Recorder All

VG4 Recorder All

VMAX A1 G4 DVR All

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Scot Berner of TrustedSec reported this vulnerability to CISA.
.