# Kenik cameras hit by path traversal flaw

Published: 2026-05-25 · Severity: medium · Sectors: manufacturing
Canonical: https://vorant.io/reports/04258a2c-145e-5e57-9de3-dcc99fa1b0b8/kenik-cameras-hit-by-path-traversal-flaw

> An unauthenticated path traversal vulnerability in Kenik camera management panels allows attackers to read arbitrary server files.

CERT Polska coordinated disclosure of CVE-2026-7766, a path traversal vulnerability affecting Kenik camera management panel software. The flaw allows an unauthenticated attacker to send a crafted GET request containing an arbitrary file path, enabling them to read files stored on the affected device's server without any credentials.

The vendor has released fixes: KG-5260xxxx-IL-(G)2 camera models were patched in firmware version 2026-04-23, while the remainder of the affected product line received fixes in version 2025-04-21. The vulnerability was responsibly reported by Łukasz Bawolski of Exea Data Center through CERT Polska's coordinated vulnerability disclosure process. No evidence of active exploitation was noted in the advisory.

## Mentioned in this report

- Vulnerabilities: CVE-2026-7766

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-7766

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/04258a2c-145e-5e57-9de3-dcc99fa1b0b8/kenik-cameras-hit-by-path-traversal-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
