CVE-2026-88622: Command Injection
Published Sep 18, 2026
·Updated
NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handleimportprivilege.php.
Affected Software
1 affected component
NUUO Network Video Recorder=2.0.0
Event History
Sep 18, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which component should be prioritized for investigation?
Investigate deployments of NUUO Network Video Recorder 2.0.0, specifically the handle_import_privilege.php endpoint or script, because it is identified as the command-injection location.
2
What is the likely security impact category?
The reported weakness is command injection. This category can allow attacker-supplied input to be interpreted as operating-system commands, though the available data does not specify the required access level, attack path, or execution privileges.