CVE-2026-12694
A critical authorization flaw in Vimesoft's Enterprise Video Platform lets attackers access functions that should be restricted. The vulnerability affects versions 3.11.0.0 up to but not including 3.25.0. No official patch or exploit is currently known.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users of Vimesoft Inc. Enterprise Video Platform versions 3.11.0.0 through 3.24.x
Real-world impact
An attacker can bypass access controls and perform unauthorized actions, potentially leading to data tampering or disruption of service.
Why this severity
CVSS 9.1 (Critical) due to network‑adjacent, low‑complexity attack with high impact on integrity and availability, but no confidentiality impact.
What to do about it
- 01No official fix is available yet.
- 02Monitor vendor advisories for a future patch.
- 03Apply the principle of least privilege and restrict network access to the platform until a fix is released.
- ›Limit exposure of the platform to trusted networks.
- ›Review and tighten ACL configurations where possible.
Remediation guidance is based solely on the provided data; no vendor patch or CISA KEV entry exists.