CVE-2026-85545 PUBLISHED

Assigner: hikvision
Reserved: 04.09.2026 Published: 10.09.2026 Updated: 10.09.2026

There is an Vulnerability in some HikCentral Access Control versions. Authenticated low-privilege users can invoke API interfaces that their role is not authorized to access.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CVSS Score: 7.1

Product Status

Vendor Hikvision
Product HikCentral Access Control
Versions
  • Version below V2.5.0(included) is affected

Credits

  • Patrick Tung (@patrickt2017) finder

References