Junglewise Threat Intelligence

CVE-2026-1749: Hikvision HikCentral Professional access control bypass

CVE-2026-1749 · Severity: medium · CVSS 6.8 · Published 2026-05-09

Vendors: Hikvision.

Executive brief

A security vulnerability has been identified in Hikvision HikCentral Professional, a centralized video management platform used to manage security cameras and access control systems. An attacker could exploit this flaw to gain administrative permissions without needing a username or password. This could allow an unauthorized person to view sensitive video feeds or modify security system settings, potentially compromising the physical security of a facility.

Technical details

An improper access control vulnerability (CWE-284) exists in Hikvision HikCentral Professional versions V2.4.0 through V3.0.1. The flaw allows an unauthenticated attacker to bypass security restrictions and obtain administrative permissions. While the attack vector is network-based, the CVSS metric indicates high complexity (AC:H), suggesting specific conditions or timing may be required to successfully exploit the vulnerability. Successful exploitation results in a complete loss of confidentiality (C:H) as the attacker gains unauthorized access to the management interface. Users are advised to update to a patched version provided by the vendor.

Affected products

  • Hikvision HikCentral Professional V2.4.0 - V3.0.1

Timeline

  • 2026-05-09: disclosed
  • 2026-05-09: advisory

References