CVE-2026-44629
largeInsecure folder permissions in Genetec Streamvault SV-100E/SV-300E and Synergis Softwire
CVE-2026-44629 is an improper access control issue (CWE-922) affecting the Synergis Softwire installation folder, meaning the directory's permissions grant more access than they should. An attacker with a low-privileged local account on the host can create or modify files in that folder; the CVSS vector (local attack vector, low privileges required, scope changed) indicates the flaw crosses a security boundary, consistent with the software running with elevated rights, so an attacker could achieve local privilege escalation with high confidentiality impact and limited integrity/availability impact. Affected deployments are Streamvault all-in-one video surveillance appliances (SV-100E and SV-300E series) and Synergis Softwire installations on Windows servers, so any organization with interactive local users on these systems is potentially exposed to privileged access on the appliance or server. No specific affected version ranges are included in the available data, so administrators must consult the Genetec advisory for affected builds. Exploitation is not currently known: there is no public proof of concept, the issue is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.1%.
What to do: Review the Genetec security advisory ([email protected] is the assigning CNA) to identify affected and fixed builds, and patch Streamvault appliance firmware and Synergis Softwire accordingly, since no version ranges are available in the data here. As an interim mitigation, restrict write access to the Synergis Softwire installation folder so only administrators and the service account can modify it, and audit which local accounts have interactive logon rights on Streamvault appliances and Softwire servers. Given no known in-the-wild exploitation and a very low EPSS score, treat this as a scheduled hardening/patching item rather than an emergency, but prioritize hosts that expose interactive logons to untrusted users.
| Genetec Streamvault all-in-one appliance, SV-100E series | — |
| Genetec Streamvault all-in-one appliance, SV-300E series | — |
| Genetec Synergis Softwire installed on Windows servers | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one appliances (SV-100E and SV-300E series) and Synergis Softwire installed on Windows servers.
- Weakness
- CWE-922
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.