PT-2026-97114 · Openeye · Apex Network Video Recorder

·

CVE-2026-94367

·

Published

2026-09-22

·

Updated

2026-09-26

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenEye Apex Network Video Recorder versions 2.2.3.4 through 3.2.9.376
Description An OS command injection issue exists in the recbackup component. An authenticated administrator can provide specially crafted backup-area configuration input that is passed to a shell command, enabling the execution of arbitrary commands with the privileges of the nvr user.
Recommendations Upgrade to version 3.5.4.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94367

Affected Products

Apex Network Video Recorder