CVE-2026-85545: High severity HikCentral Access Control vulnerability
Published Sep 10, 2026
·Updated
There is an Vulnerability in some HikCentral Access Control versions. Authenticated low-privilege users can invoke API interfaces that their role is not authorized to access.
Affected Software
1 affected component
HikCentral Access Control
Event History
Sep 10, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
DescriptionSeverity
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must already be authenticated as a low-privilege user. The vulnerability is remotely reachable and does not require user interaction.
2
What is the likely impact of successful exploitation?
A low-privilege user may be able to invoke API interfaces that their assigned role is not authorized to access. The provided severity vector indicates high confidentiality impact and low integrity impact, with no availability impact stated.