ZeroHour

CVE-2026-85545

large

Broken access control in Hikvision HikCentral Access Control API

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-85545 is an improper authorization (broken access control) flaw in some versions of Hikvision's HikCentral Access Control management software. An attacker with valid credentials for a low-privilege account can send network requests to API interfaces that their assigned role is not authorized to use, bypassing role-based restrictions. Per the CVSS 3.1 score (7.1, AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N), successful abuse yields high-impact information disclosure with limited integrity changes, with no availability impact. Any organization running an affected HikCentral Access Control version is affected, especially where the management server is reachable beyond a trusted internal network. There is no public proof-of-concept, the issue is not in CISA's KEV catalog, and no in-the-wild exploitation is currently known.

What to do: Check the Hikvision HSRC advisory for CVE-2026-85545 to identify the exact affected and fixed versions and upgrade affected HikCentral Access Control servers accordingly. Until patched, restrict network and internet exposure of the HikCentral server and review audit logs for low-privilege accounts invoking higher-privileged API endpoints.

Affected
Hikvision HikCentral Access Control
Estimated exposure
large≈tens of thousands of deployments (Hikvision access-control installations worldwide) — Hikvision is one of the world's largest access control and video security vendors with a broad on-premises installed base, and public internet scans regularly show tens of thousands of exposed Hikvision management endpoints, though exact…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

There is an Vulnerability in some HikCentral Access Control versions. Authenticated low-privilege users can invoke API interfaces that their role is not authorized to access.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.