HIGHCVE-2026-1241Published Modified CNA icscert
CVE-2026-1241: Authentication Bypass Using an Alternate Path or Channel in Pelco, Inc. Sarix Pro 3 Series IP Cameras
The Pelco, Inc. Sarix Professional 3 Series Cameras are vulnerable to an authentication bypass issue in their web management interface. The flaw stems from inadequate enforcement of access controls, allowing certain functionality to be accessed without proper authentication. This weakness can lead to unauthorized viewing of live video streams, creating privacy concerns and operational risks for organizations relying on these cameras. Additionally, it may expose operators to regulatory and compliance challenges.
Metrics
- CVSS v4.0
- 8.7
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 4
Affected packages
- Pelco, Inc. / Sarix Professional IMP 3 Series≤ 02.52
- Pelco, Inc. / Sarix Professional IXP 3 Series≤ 02.52
- Pelco, Inc. / Sarix Professional IBP 3 Series≤ 02.52
- Pelco, Inc. / Sarix Professional IWP 3 Series≤ 02.52
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NReferences