The Pelco, Inc. Sarix Professional 3 Series Cameras are vulnerable to an authentication bypass issue in their web management interface. The flaw stems from inadequate enforcement of access controls, allowing certain functionality to be accessed without proper authentication. This weakness can lead to unauthorized viewing of live video streams, creating privacy concerns and operational risks for organizations relying on these cameras. Additionally, it may expose operators to regulatory and compliance challenges.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Pelco, Inc. recommends that all Sarix Professional 3 Series Camera users update their camera firmware to version 02.53 or later. Installing the latest firmware ensures your device receives the most up-to-date bug fixes and critical security enhancements. More information can be found by visiting Pelco, Inc's technical support page ( https://www.pelco.com/support ) for assistance.


Workaround

No workaround given by the vendor.

History

Thu, 26 Feb 2026 20:00:00 +0000

Type Values Removed Values Added
Description The Pelco, Inc. Sarix Professional 3 Series Cameras are vulnerable to an authentication bypass issue in their web management interface. The flaw stems from inadequate enforcement of access controls, allowing certain functionality to be accessed without proper authentication. This weakness can lead to unauthorized viewing of live video streams, creating privacy concerns and operational risks for organizations relying on these cameras. Additionally, it may expose operators to regulatory and compliance challenges.
Title Authentication Bypass Using an Alternate Path or Channel in Pelco, Inc. Sarix Pro 3 Series IP Cameras
Weaknesses CWE-288
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-02-26T20:43:53.216Z

Reserved: 2026-01-20T18:26:34.854Z

Link: CVE-2026-1241

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-26T20:31:33.657

Modified: 2026-02-26T20:31:33.657

Link: CVE-2026-1241

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses