CVE-2026-1241 describes an authentication bypass vulnerability in the web management interface of Pelco, Inc. Sarix Professional 3 Series Cameras. This flaw allows unauthorized access to certain functionalities, including live video streams, due to inadequate access control enforcement. Rated 8.7 HIGH on the CVSS scale, this network-based vulnerability requires no user interaction and could lead to significant privacy concerns and operational risks. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Pelco, Inc. | Sarix Professional IBP 3 Series | >= 0, <= 02.52CNA affecteddefault unaffected | |
| Pelco, Inc. | Sarix Professional IMP 3 Series | >= 0, <= 02.52CNA affecteddefault unaffected | |
| Pelco, Inc. | Sarix Professional IWP 3 Series | >= 0, <= 02.52CNA affecteddefault unaffected | |
| Pelco, Inc. | Sarix Professional IXP 3 Series | >= 0, <= 02.52CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.