Junglewise Threat Intelligence

CVE-2026-40619: Genetec Security Center information disclosure in installation logs

CVE-2026-40619 · Severity: high · CVSS 7.8 · Published 2026-06-02

Technologies: Genetec Security Center. Vendors: Genetec.

Executive brief

A security vulnerability has been identified in Genetec Security Center main server installations where administrative credentials may be stored in plain text within installation logs. An attacker who already has local access to the server could retrieve these credentials to gain full administrative control over the security system. This issue affects specific installation packages for versions 5.7 through 5.13, and organizations are advised to rotate passwords and use the provided cleanup utility.

Technical details

A sensitive information disclosure vulnerability (CWE-532) exists in the installation process of Genetec Security Center main servers. The Server Admin password may be captured in plain text within installation logs located in the ProgramData directory (or custom silent install locations) under specific conditions. An attacker with local OS privileges can read these logs to obtain administrative credentials for the Security Center application. The vulnerability affects new deployments of versions 5.7 SR6 through 5.13.3; however, Genetec released remediated builds under the same version numbers in May 2026, requiring hash verification to confirm exposure. Remediation involves rotating the admin password and running the 'SecurityUtility_CVE-2026-40619_SAM.exe' tool to purge the logs.

Affected products

  • Genetec Security Center 5.7 SR6 to 5.13.3 (specific builds)

Timeline

  • 2026-05-13: patched: Remediated builds for 5.11.3 and 5.12.2 released
  • 2026-05-14: patched: Remediated builds for 5.13.3 released
  • 2026-05-21: patched: Remediated builds for 5.10.4 released
  • 2026-06-02: advisory: Initial public disclosure by Genetec

References

Related threats