CVE-2026-40619: High severity Genetec Security Center Main Server vulnerability

Published Jun 2, 2026
·
Updated

A high security vulnerability affecting Security Center main server installations has been identified. It could allow an attacker with local OS privileges to the main server to access the Server Admin credentials. A third party hired by Genetec found the issue. There is currently no evidence of active exploitation.

This vulnerability is associated with specific installation package builds rather than the product version identifier alone. Certain versions (including 5.10.4.0, 5.11.3.0, 5.12.2.0 and 5.13.3.0) were released with both vulnerable and remediated installation packages under the same version number.

Consequently, version-based comparison alone is insufficient to determine exposure. Only installations performed using vulnerable builds are affected. Remediated builds can be distinguished using verified installation package hashes. For the complete list of fixed build hashes, refer to the security advisory section.

Affected Software

1 affected component
Genetec Security Center Main Server

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 5.10.4.0
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 5.11.3.0
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 5.12.2.0
  4. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 5.13.3.0
  5. Configuration

    For affected versions where both vulnerable and remediated packages were released under the same version number, verify installation package integrity against the confirmed remediated build hashes from the security advisory. If the package hash does not match a known remediated value, consider the installation vulnerable.

    Genetec Security Center main server installations Installation package integrity (hash verification) = Match against remediated build hashes
  6. Operational

    If you previously installed using a vulnerable build, plan to reinstall/replace with the updated remediated installation package build (the vulnerability allows local OS–privileged attackers to access Server Admin credentials).

Event History

Jun 2, 2026
CVE Published
via MITRE·02:37 PM
Data Sourced
via MITRE·02:37 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-40619?

CVE-2026-40619 has a high severity rating of 7.8.

2

What does CVE-2026-40619 entail?

CVE-2026-40619 is a vulnerability that allows an attacker with local OS privileges to access the Server Admin credentials on the Security Center main server.

3

How do I fix CVE-2026-40619?

To fix CVE-2026-40619, install the updated installation packages that have been released for affected versions of Security Center.

4

Who identified CVE-2026-40619?

CVE-2026-40619 was identified by a third party hired by Genetec.

5

Is there evidence of exploitation for CVE-2026-40619?

Currently, there is no evidence of active exploitation for CVE-2026-40619.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203