CVE-2026-85545
largeBroken access control in Hikvision HikCentral Access Control API
CVE-2026-85545 is an improper authorization (broken access control) flaw in some versions of Hikvision's HikCentral Access Control management software. An attacker with valid credentials for a low-privilege account can send network requests to API interfaces that their assigned role is not authorized to use, bypassing role-based restrictions. Per the CVSS 3.1 score (7.1, AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N), successful abuse yields high-impact information disclosure with limited integrity changes, with no availability impact. Any organization running an affected HikCentral Access Control version is affected, especially where the management server is reachable beyond a trusted internal network. There is no public proof-of-concept, the issue is not in CISA's KEV catalog, and no in-the-wild exploitation is currently known.
What to do: Check the Hikvision HSRC advisory for CVE-2026-85545 to identify the exact affected and fixed versions and upgrade affected HikCentral Access Control servers accordingly. Until patched, restrict network and internet exposure of the HikCentral server and review audit logs for low-privilege accounts invoking higher-privileged API endpoints.
| Hikvision HikCentral Access Control | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
There is an Vulnerability in some HikCentral Access Control versions. Authenticated low-privilege users can invoke API interfaces that their role is not authorized to access.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.