CVE-2026-17612
MEDIUMHoneywell S35 Series 3M/5M/8M/PinHole Cameras - Audit Log Exposure Through Unauthorized Access
Title source: ruleDescription
Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14.20260207 contains an audit log disclosure Vulnerability that could allow an attacker to access audit logs without authentication, potentially resulting in the disclosure of sensitive information. Honeywell recommends updating to the latest available version (HC5.26.1.16.20260207) once available.
References (1)
Core 1
Scores
CVSS v4
6.9
EPSS
0.0031
EPSS Percentile
23.1%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Products (1)
Honeywell/S35 Series 3M/5M/8M/PinHole Cameras
HC4.25.1.27.20250728 - HC5.26.1.14.20260207
Published
Jul 27, 2026
Tracked Since
Jul 28, 2026