Executive brief
HikCentral Access Control is an access management system used to control physical entry points and security in facilities. Authenticated users with limited privileges can bypass role-based access controls to invoke API functions they should not have permission to use, potentially allowing them to modify security policies, grant themselves higher privileges, or access sensitive building security data.
Technical details
This vulnerability is a privilege escalation issue in HikCentral Access Control caused by insufficient authorization checks on API endpoints. Authenticated users with low-privilege roles can invoke API interfaces that their role is not authorized to access, bypassing role-based access control (RBAC) mechanisms. The attack requires a valid authentication credential but no additional preconditions. An attacker with a standard user account could escalate privileges to perform administrative actions, compromise the integrity of access control policies, or retrieve sensitive security configuration data. Patches are expected to be available from Hikvision.
Affected products
- Hikvision HikCentral Access Control some versions
Timeline
- 2026-09-10: disclosed