CVE-2026-17612

MEDIUM

Honeywell S35 Series 3M/5M/8M/PinHole Cameras - Audit Log Exposure Through Unauthorized Access

Title source: rule
STIX 2.1

Description

Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14.20260207 contains an audit log disclosure Vulnerability that could allow an attacker to access audit logs without authentication, potentially resulting in the disclosure of sensitive information. Honeywell recommends updating to the latest available version (HC5.26.1.16.20260207) once available.

Scores

CVSS v4 6.9
EPSS 0.0031
EPSS Percentile 23.1%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
Honeywell/S35 Series 3M/5M/8M/PinHole Cameras HC4.25.1.27.20250728 - HC5.26.1.14.20260207
Published Jul 27, 2026
Tracked Since Jul 28, 2026