CVE-2026-12692
CVE-2026-12692 is a critical vulnerability (CVSS 9.8) in Vimesoft Inc. Enterprise Video Platform. It allows attackers to bypass authentication by exploiting an unverified password change process. The flaw affects versions from 3.11.0.0 up to but not including 3.25.0, with no official fix available yet.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Vimesoft Inc. Enterprise Video Platform versions 3.11.0.0 to 3.24.0
Real-world impact
Authentication bypass could lead to unauthorized access or control of the system
Why this severity
CVSS 9.8 (critical): High confidence in exploitation, high impact on confidentiality, integrity, and availability
What to do about it
- 01Upgrade to version 3.25.0 or later when available
- 02Apply vendor-recommended mitigations if no patch exists
- ›Restrict access to password change functionality
- ›Monitor for suspicious authentication attempts
Based on NVD description and CVE details. No CISA KEV or public exploit reported.