Junglewise Threat Intelligence

CVE-2026-25112: Genetec RabbitMQ privilege escalation in multiple products

CVE-2026-25112 · Severity: high · CVSS 7.8 · Published 2026-05-26

Vendors: Genetec.

Executive brief

A security vulnerability exists in how Genetec products deploy RabbitMQ, a messaging component used for communication between different parts of the security system. If an attacker has local access to the server, they could exploit incorrect file permissions to gain administrative control over the machine. This could lead to unauthorized access to security data, service disruptions, or full system compromise.

Technical details

The vulnerability is classified as an incorrect permission assignment (CWE-732) within the RabbitMQ deployment used by various Genetec products. RabbitMQ relies on a diagnostic utility that, if replaced or shadowed by an untrusted component in a specific directory (ProgramData\Genetec\RabbitMQ), will execute that component with the elevated privileges of the RabbitMQ service. An attacker with local access and low-level privileges can exploit this to achieve full system authority. The issue affects Genetec-provided RabbitMQ versions 3.13.7.3 and earlier. A mitigation utility is available for existing deployments, and version 3.13.7.19 provides a permanent fix.

Affected products

  • Genetec RabbitMQ 3.13.7.3 and earlier
  • Genetec Mission Control 3.4.1.0 and earlier
  • Genetec Industrial IoT (IIoT) 5.x 5.5.118.0 and earlier
  • Genetec Industrial IoT (IIoT) 6.x 6.0.196.0 and earlier
  • Genetec Airport Operational Manager (AOM) 1.6 and earlier
  • Genetec Restricted Security Area (RSA) Surveillance 5.2.1 and earlier
  • Genetec Inter-System (IS) Gateway 1.2 and earlier
  • Genetec Sipelia 2.11 and earlier

Timeline

  • 2026-05-25: advisory: Genetec published the security advisory.
  • 2026-05-26: disclosed: CVE-2026-25112 published to NVD.

References