VORANT. Threat Intelligence Sign in Get the full feed

Kenik cameras hit by path traversal flaw

medium vulnerability manufacturing

An unauthenticated path traversal vulnerability in Kenik camera management panels allows attackers to read arbitrary server files.

CERT Polska coordinated disclosure of CVE-2026-7766, a path traversal vulnerability affecting Kenik camera management panel software. The flaw allows an unauthenticated attacker to send a crafted GET request containing an arbitrary file path, enabling them to read files stored on the affected device's server without any credentials.

The vendor has released fixes: KG-5260xxxx-IL-(G)2 camera models were patched in firmware version 2026-04-23, while the remainder of the affected product line received fixes in version 2025-04-21. The vulnerability was responsibly reported by Łukasz Bawolski of Exea Data Center through CERT Polska's coordinated vulnerability disclosure process. No evidence of active exploitation was noted in the advisory.

Mentioned in this report

Vulnerabilities CVE-2026-7766

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-7766

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free