Junglewise Threat Intelligence

CVE-2026-94367: OpenEye Apex Network Video Recorder OS command injection in recbackup

CVE-2026-94367 · Severity: high · CVSS 7.2 · Published 2026-09-23

Technologies: OpenEye Apex Network Video Recorder. Vendors: OpenEye.

Executive brief

OpenEye Apex is a network video recorder that stores and manages surveillance footage from security cameras. An authenticated administrator can inject arbitrary operating system commands through backup configuration settings, gaining unauthorized code execution on the recorder with system-level privileges. This could allow an attacker with admin credentials to gain control of the entire surveillance system and access sensitive recordings.

Technical details

The recbackup component fails to properly sanitize backup-area configuration input before passing it to a shell command, enabling OS command injection. An authenticated administrator account is required to exploit this vulnerability. Successful exploitation allows arbitrary command execution with nvr user privileges on the device. A fix is available in firmware 3.4.3 and later (advisory notes 3.5.4 as current).

Affected products

  • OpenEye Apex Network Video Recorder 3.2.9.376 and earlier (vulnerable since at least 2.2.3.4); fixed in 3.4.3 and later

Timeline

  • 2026-09-23: disclosed
  • 2026: patched: Fixed in firmware 3.4.3 and later

References

Related threats