PT-2026-97112 · Openeye · Apex Network Video Recorder

·

CVE-2026-92929

·

Published

2026-09-22

·

Updated

2026-09-23

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenEye Apex Network Video Recorder versions 2.2.3.4 through 3.2.9.376
Description The software trusts an X-Forwarded-For header provided by a client to determine the request source address. This allows an unauthenticated remote attacker to spoof a loopback address and bypass security controls that restrict access to local connections on non-TLS web interfaces, leading to the disclosure of configuration information.
Recommendations Upgrade to version 3.5.4.

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92929

Affected Products

Apex Network Video Recorder