{"dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": {"cveId": "CVE-2026-94367", "assignerOrgId": "c35fbbdf-8d87-49b6-8120-920a36e62b7f", "state": "PUBLISHED", "assignerShortName": "Securifera", "dateReserved": "2026-09-21T11:08:29.152Z", "datePublished": "2026-09-22T23:10:19.304Z", "dateUpdated": "2026-09-22T23:19:17.038Z"}, "containers": {"cna": {"problemTypes": [{"descriptions": [{"lang": "en", "type": "CWE", "cweId": "CWE-78", "description": "CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"}]}], "affected": [{"vendor": "OpenEye", "product": "Apex Network Video Recorder (NVR)", "versions": [{"version": "3.2.9.376", "status": "affected"}], "defaultStatus": "unknown"}], "descriptions": [{"lang": "en", "value": "OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup. An authenticated administrator can supply crafted backup-area configuration input that is passed to a shell command, allowing commands to execute with the privileges of the nvr user. The underlying design has been present since at least firmware 2.2.3.4.\n\nUpgrade to version 3.5.4."}], "metrics": [{"format": "CVSS", "scenarios": [{"lang": "en", "value": "GENERAL"}], "cvssV3_1": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH", "baseScore": 7.2, "baseSeverity": "HIGH"}}], "references": [{"url": "https://portal.openeye.net/updates/issue-alerts/1061"}, {"url": "https://www.securifera.com/advisories/"}], "solutions": [{"lang": "en", "value": "Upgrade to version 3.5.4."}], "credits": [{"lang": "en", "value": "Ryan Wincey (@rwincey, Securifera)", "type": "finder"}], "providerMetadata": {"orgId": "c35fbbdf-8d87-49b6-8120-920a36e62b7f", "shortName": "Securifera", "dateUpdated": "2026-09-22T23:19:17.038Z"}}}}