Kenik Camera Panels Can Read Server Files

The problem is not a broken camera view. An unauthenticated request to the Kenik camera management panel can pull arbitrary files from the server, so exposed panels can leak configuration and other readable internal files, not just video or UI data. CERT Polska disclosed CVE-2026-7766 and says the issue was fixed in KG-5260xxxx-IL-(G)2 cameras in version 2026-04-23. Other Kenik products were fixed in version 2025-04-21.

Part of the PlainSec briefing for 2026-05-25

Sources