Kenik cameras hit by path traversal flaw
An unauthenticated path traversal vulnerability in Kenik camera management panels allows attackers to read arbitrary server files.
CERT Polska coordinated disclosure of CVE-2026-7766, a path traversal vulnerability affecting Kenik camera management panel software. The flaw allows an unauthenticated attacker to send a crafted GET request containing an arbitrary file path, enabling them to read files stored on the affected device's server without any credentials.
The vendor has released fixes: KG-5260xxxx-IL-(G)2 camera models were patched in firmware version 2026-04-23, while the remainder of the affected product line received fixes in version 2025-04-21. The vulnerability was responsibly reported by Łukasz Bawolski of Exea Data Center through CERT Polska's coordinated vulnerability disclosure process. No evidence of active exploitation was noted in the advisory.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-7766
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free