CVE-2026-6824
HIGHCVSS 8.4/10EPSS 0.37%
Last modified
This CVE is reserved or awaiting analysis. Details will appear once published by NVD.
Description
A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input in specific functional modules. Attackers can inject malicious scripts, which are then persistently stored on the device backend. When administrators or users access affected pages, the stored scripts are executed in their browsers, leading to potential session hijacking, unauthorized actions, or data theft.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Are you affected by CVE-2026-6824?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
