Arbitrary Database Query Execution in Shinobi Surveillance Software by Shinobi Systems
CVE-2026-82448
9.3CRITICAL
What is CVE-2026-82448?
The Shinobi surveillance software prior to commit 5a76c74f contains a security flaw stemming from a hardcoded connection key in its child node service. This vulnerability allows unauthenticated attackers to remotely execute arbitrary SQL queries by establishing a connection through the child node port and utilizing the hardcoded key during the WebSocket handshake. By exploiting this defect, attackers can manipulate user records and alter camera configurations, posing a significant risk to system integrity and user privacy.
Affected Version(s)
Shinobi 0 < 5a76c74f3977661ff3f9fd55a260db352c0b19c0
