CVE-2026-65422: Medium severity Genetec Security Center vulnerability
Published Sep 24, 2026
·Updated
A flaw in the authorization mechanism for Media Gateway API in Genetec Security Center may allow a user with no playback privileges to generate video thumbnails.
Affected Software
1 affected component
Genetec Security Center
Event History
Sep 24, 2026
CVE Published
via MITRE·02:39 PM
Data Sourced
via MITRE·02:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs an existing user account with low privileges. The flaw allows a user who lacks playback privileges to generate video thumbnails through the Media Gateway API.
2
What information could be exposed?
The impact is limited to confidentiality: unauthorized users may be able to obtain video thumbnails. The provided severity vector does not indicate an integrity or availability impact.
3
Can this be exploited remotely or does it require user interaction?
The vulnerability is network-accessible and has low attack complexity. It does not require user interaction, but it does require low-level privileges.