AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-4757

HIGH · CVSS 7.2 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability exists in the VAPIX API due to improper input validation, which could enable authenticated attackers with administrator privileges to execute arbitrary code and potentially escalate their privileges. Organizations using affected products should prioritize patching this flaw to mitigate the risk of unauthorized access and control over their systems. Immediate attention is recommended for environments where administrator accounts are in use.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-4757
Severity
HIGH
CVSS
7.2
EPSS
0.39%

Original NVD Description

A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can only be exploited after authenticating with an administrator-privileged service account.