Vulnary
← back to the feed
Critical· 9.1

CVE-2026-12694

A critical authorization flaw in Vimesoft's Enterprise Video Platform lets attackers access functions that should be restricted. The vulnerability affects versions 3.11.0.0 up to but not including 3.25.0. No official patch or exploit is currently known.

publishedJul 17, 2026
last modifiedJul 17, 2026
sourcesNVD
severity · cvss
9.1
critical · how bad it is
exploitation · epss
<1%
16th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 1, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Users of Vimesoft Inc. Enterprise Video Platform versions 3.11.0.0 through 3.24.x

02

Real-world impact

An attacker can bypass access controls and perform unauthorized actions, potentially leading to data tampering or disruption of service.

03

Why this severity

CVSS 9.1 (Critical) due to network‑adjacent, low‑complexity attack with high impact on integrity and availability, but no confidentiality impact.

04

What to do about it

no official fix yet
recommended steps
  1. 01No official fix is available yet.
  2. 02Monitor vendor advisories for a future patch.
  3. 03Apply the principle of least privilege and restrict network access to the platform until a fix is released.
interim mitigations
  • Limit exposure of the platform to trusted networks.
  • Review and tighten ACL configurations where possible.

Remediation guidance is based solely on the provided data; no vendor patch or CISA KEV entry exists.

05

Timeline

06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactNone
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →