CVE-2026-84398
CVE-2026-84398 is a high-severity vulnerability with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-258.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- CVSS v4: 8.7
- EPSS exploit prediction: 0% (33rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-258
- Published:
- Last modified:
Description
CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration information.
Frequently asked questions
- What is CVE-2026-84398?
- CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration information.
- How severe is CVE-2026-84398?
- CVE-2026-84398 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2026-84398 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (33rd percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-84398?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-84398 published?
- CVE-2026-84398 was published on 2026-09-18 and last updated on 2026-09-19.
References
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-258-08.json
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-08
Other CWE-258 vulnerabilities
- CVE-2025-9276 — Critical (CVSS 9.8): Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability. This vulnerability…
- CVE-2019-5021 — Critical (CVSS 9.8): Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This…
- CVE-2018-17914 — Critical (CVSS 9.8): InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior…
- CVE-2024-28744 — High (CVSS 8.8): The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24…
- CVE-2023-39439 — High (CVSS 8.8): SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to log into…
- CVE-2020-29478 — High (CVSS 7.5): CA Service Catalog 17.2 and 17.3 contain a vulnerability in the default configuration of the Setup Utility that may…