Authentication Bypass in OpenEye Apex NVR Firmware
CVE-2026-92929

5.3MEDIUM

Key Information:

Vendor

Openeye

Vendor
CVE Published:
22 September 2026

What is CVE-2026-92929?

The OpenEye Apex Network Video Recorder firmware version 3.2.9.376 has a vulnerability related to the way it handles the X-Forwarded-For header provided by clients. An attacker can exploit this flaw to bypass local security measures that restrict access to sensitive configuration information through non-TLS web interfaces. This threat can lead to unauthorized exposure of data, affecting the overall security of the device. The flaw has existed since at least firmware version 2.2.3.4, emphasizing the importance of timely firmware updates. Users are recommended to upgrade to version 3.5.4 to mitigate risks.

Affected Version(s)

Apex Network Video Recorder (NVR) 3.2.9.376

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ryan Wincey (@rwincey, Securifera)
.