Executive brief
A security flaw in Genetec Security Center, a unified security platform used for video surveillance and access control, allows unauthorized individuals to view live video feeds. An attacker could exploit this weakness over the network without needing a username or password. This could lead to significant privacy breaches and the unauthorized monitoring of sensitive facilities or operations.
Technical details
An improper authentication vulnerability (CWE-287) exists in the video retrieval services of Genetec Security Center 5.14.0.0. The flaw stems from a failure in the validation logic for video stream requests, resulting in incomplete verification of client authentication tokens. A remote, unauthenticated attacker can exploit this by sending specially crafted requests to the video management service to retrieve live video content. While video encryption (fusion stream) can mitigate the impact by preventing playback, the underlying authentication bypass remains present until the mandatory hotfix (build 5.14.178.18) is applied.
Affected products
- Genetec Security Center 5.14.0.0 build 5.14.178.8 up to (but not including) 5.14.178.18
Timeline
- 2026-07-06: disclosed
- 2026-07-06: advisory
- 2026-07-06: patched: Mandatory hotfix 5.14.178.18 released