| CVE ID | CVE-2026-7766 |
| Publication date | 25 May 2026 |
| Vendor | Kenik |
| Product | KG-5230TAS-IL-3, KG-5230TAS-IL-G3, KG-5230DAS-IL-G3, KG-5260TZAS-IL-3, KG-5260DZAS-IL-3, KG-5260TZAS-IL-G3, KG-5260DZAS-IL-G3, KG-5260xxxx-IL-(G)2 |
| Vulnerable versions | All before 2025-04-21 |
| Vulnerability type (CWE) | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Kenik Kenik cameras software and participated in coordination of its disclosure.
The vulnerability CVE-2026-7766: Kenik Camera management panel is vulnerable to Path Traversal vulnerability. An unauthenticated attacker can send GET request with arbitrary file path and read corresponding files located on the server.
The issue was fixed in version 2026-04-23 of the KG-5260xxxx-IL-(G)2 cameras. Rest of the products were fixed in version 2025-04-21.
Credits
We thank Łukasz Bawolski (Exea Data Center) for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.