Junglewise Threat Intelligence

CVE-2026-44629: Genetec Synergis Softwire improper access control in installation folder

CVE-2026-44629 · Severity: high · CVSS 7.9 · Published 2026-08-28

Vendors: Genetec.

Executive brief

Synergis Softwire is a security software component used in Streamvault surveillance appliances and Windows server deployments. A flaw in access controls allows unauthorized users to access sensitive files in the Softwire installation directory, potentially exposing credentials, configuration data, or enabling lateral movement within a security infrastructure.

Technical details

This vulnerability is an improper access control flaw affecting the Synergis Softwire installation folder on both Streamvault all-in-one appliances (SV-100E and SV-300E series) and Windows server installations. The root cause is inadequate permission checks on the installation directory, allowing users with local access to read or modify sensitive files without proper authentication. An attacker with local system access can exploit this to access protected configuration files or credentials. The vulnerability has been resolved in Synergis Softwire versions 12.0.2 and 12.2.0 or later.

Affected products

  • Genetec Synergis Softwire below 12.0.2, below 12.2.0
  • Genetec Streamvault SV-100E <UNKNOWN>
  • Genetec Streamvault SV-300E <UNKNOWN>

Timeline

  • 2026-08-28: disclosed

References