CVE-2026-1749
Received
Received - Intake
Access Control Flaw in HikCentral Professional
Publication date: 2026-05-09
Last updated on: 2026-05-09
Assigner: Hangzhou Hikvision Digital Technology Co., Ltd.
Description
Description
There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permission.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hikvision | hikcentral_professional | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Access Control Vulnerability found in some versions of HikCentral Professional. It allows an unauthenticated user to gain admin permissions without proper authorization.
How can this vulnerability impact me? :
An attacker exploiting this vulnerability could obtain administrative privileges on the affected HikCentral Professional system without authentication. This could lead to unauthorized access, control over the system, and potential misuse of sensitive data or system functions.
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70