CVE-2026-4606: GeoVision ERM Improper Privilege Assignment Leads to SYSTEM-Level Privilege

Published Mar 23, 2026
·
Updated

GV Edge Recording Manager (ERM) v2.3.1 improperly runs application components with SYSTEM-level privileges, allowing any local user to gain full control of the operating system.

During installation, ERM creates a Windows service that runs under the LocalSystem account.

When the ERM application is launched, related processes are spawned under SYSTEM privileges rather than the security context of the logged-in user.

Functions such as 'Import Data' open a Windows file dialog operating with SYSTEM permissions, enabling modification or deletion of protected system files and directories.

Any ERM function invoking Windows file open/save dialogs exposes the same risk.

This vulnerability allows local privilege escalation and may result in full system compromise.

Affected Software

1 affected component
GeoVision GV Edge Recording Manager (ERM)=2.3.1

Event History

Mar 23, 2026
CVE Published
via MITRE·01:05 AM
Data Sourced
via MITRE·01:05 AM
DescriptionWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeakness
Apr 7, 58249
Event
via FIRST·02:39 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-4606?

CVE-2026-4606 has a high severity rating due to the potential for unauthorized access to SYSTEM-level privileges.

2

How do I fix CVE-2026-4606?

To fix CVE-2026-4606, upgrade to a patched version of GeoVision GV Edge Recording Manager that addresses the privilege assignment issue.

3

What systems are affected by CVE-2026-4606?

CVE-2026-4606 specifically affects GeoVision GV Edge Recording Manager version 2.3.1.

4

What does CVE-2026-4606 allow an attacker to do?

CVE-2026-4606 allows a local user to gain full control of the operating system due to improper privilege assignment.

5

Is CVE-2026-4606 exploited remotely?

CVE-2026-4606 is not exploited remotely; it requires local access to the system to leverage the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203