CVE-2026-1749
Received Received - Intake
Access Control Flaw in HikCentral Professional

Publication date: 2026-05-09

Last updated on: 2026-05-09

Assigner: Hangzhou Hikvision Digital Technology Co., Ltd.

Description
There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permission.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-09
Last Modified
2026-05-09
Generated
2026-05-09
AI Q&A
2026-05-09
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
hikvision hikcentral_professional *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is an Access Control Vulnerability found in some versions of HikCentral Professional. It allows an unauthenticated user to gain admin permissions without proper authorization.


How can this vulnerability impact me? :

An attacker exploiting this vulnerability could obtain administrative privileges on the affected HikCentral Professional system without authentication. This could lead to unauthorized access, control over the system, and potential misuse of sensitive data or system functions.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart