CVE-2026-7766 PUBLISHED

Path Traversal in Kenik cameras

Assigner: CERT-PL
Reserved: 04.05.2026 Published: 25.05.2026 Updated: 25.05.2026

Kenik Camera management Panel is vulnerable to Path Traversal vulnerability. An unauthenticated attacker can send GET request with arbitrary file path and read corresponding files located on the server.

The issue was fixed in version 2026-04-23 of the KG-5260xxxx-IL-(G)2 cameras. Rest of the products were fixed in version 2025-04-21.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
CVSS Score: 8.3

Product Status

Vendor Kenik
Product KG-5230TAS-IL-3
Versions Default: unaffected
  • affected from 0 to 2025-04-21 (excl.)
Vendor Kenik
Product KG-5230TAS-IL-G3
Versions Default: unaffected
  • affected from 0 to 2025-04-21 (excl.)
Vendor Kenik
Product KG-5230DAS-IL-G3
Versions Default: unaffected
  • affected from 0 to 2025-04-21 (excl.)
Vendor Kenik
Product KG-5260TZAS-IL-3
Versions Default: unaffected
  • affected from 0 to 2025-04-21 (excl.)
Vendor Kenik
Product KG-5260DZAS-IL-3
Versions Default: unaffected
  • affected from 0 to 2025-04-21 (excl.)
Vendor Kenik
Product KG-5260TZAS-IL-G3
Versions Default: unaffected
  • affected from 0 to 2025-04-21 (excl.)
Vendor Kenik
Product KG-5260DZAS-IL-G3
Versions Default: unaffected
  • affected from 0 to 2025-04-21 (excl.)
Vendor Kenik
Product KG-5260xxxx-IL-(G)2
Versions Default: unaffected
  • affected from 0 to 2026-04-23 (excl.)

Credits

  • Łukasz Bawolski (Exea Data Center) finder

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE

Impacts

  • CAPEC-126 Path Traversal