CVE-2026-17612: Audit Log Exposure through Unauthorized Access
Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14.20260207 contains an audit log disclosure Vulnerability that could allow an attacker to access audit logs without authentication, potentially resulting in the disclosure of sensitive information. Honeywell recommends updating to the latest available version (HC5.26.1.16.20260207) once available.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Honeywell S35 Series 3M/5M/8M/PinHole Camerasto a version that resolves this vulnerability.Fixed in HC5.26.1.16.20260207
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17612?
The severity of CVE-2026-17612 is classified as medium with a CVSS score of 6.9.
How do I fix CVE-2026-17612?
To fix CVE-2026-17612, update the Honeywell S35 Series Cameras to version HC5.26.1.14.20260207 or later.
What is the impact of CVE-2026-17612?
CVE-2026-17612 allows unauthorized access to sensitive audit logs, leading to potential information disclosure.
Which software is affected by CVE-2026-17612?
CVE-2026-17612 affects all versions of Honeywell S35 Series 3M, 5M, 8M, and PinHole Cameras prior to version HC5.26.1.14.20260207.
Is CVE-2026-17612 likely to be exploited?
Given its medium severity and potential for unauthorized access to sensitive information, CVE-2026-17612 may be a target for attackers.