Junglewise Threat Intelligence

CVE-2026-32684: Hikvision Application incorrect directory permissions

CVE-2026-32684 · Severity: low · CVSS 2.9 · Published 2026-05-12

Vendors: Hikvision.

Executive brief

A Hikvision application fails to properly restrict access to its internal directories. This could allow other malicious software already present on the same device to access sensitive information stored by the application. While the risk is rated as low, it represents a potential breach of data privacy on the affected system.

Technical details

The vulnerability is classified as an incorrect permission assignment for a critical resource (CWE-732). It occurs because the application's directory access permissions are overly permissive. An attacker with local access to the system could leverage another malicious application to read sensitive data from these directories. The attack complexity is considered high, and while no specific user privileges are required, the attacker must already have the ability to execute code locally on the device. Hikvision has acknowledged the issue, though specific version fixes should be verified through their official support channels.

Affected products

  • Hikvision Hikvision Application

Timeline

  • 2026-05-12: disclosed: Initial publication of the CVE record.
  • 2026-06-02: advisory: CISA-ADP enrichment and CWE assignment.

References