Description
Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14.20260207 contains an audit log disclosure Vulnerability that could allow an attacker to access audit logs without authentication, potentially resulting in the disclosure of sensitive information. Honeywell recommends updating to the latest available version (HC5.26.1.16.20260207) once available.
Published: 2026-07-27
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Honeywell S35 Series cameras, all firmware versions through HC5.26.1.14.20260207, contain an audit log disclosure flaw that permits reading of audit logs without any authentication. This weakness falls under CWE‑200 and could leak operational details such as user activity and configuration changes. The impact is strictly information disclosure; no direct code execution or integrity compromise is described.

Affected Systems

Honeywell S35 Series 3M/5M/8M/PinHole Cameras operating on firmware HC5.26.1.14.20260207 or earlier are vulnerable. Firmware HC5.26.1.16.20260207, released as a fix, removes the flaw.

Risk and Exploitability

The CVSS score of 6.9 indicates medium severity. The EPSS score of less than 1% implies a very low probability that this vulnerability is actively exploited in the wild. Because audit logs can be retrieved without authentication, the vulnerability is only exploitable when the camera is reachable over the network; if the device is isolated behind strict segmentation, the risk is greatly reduced. The flaw is not listed in the CISA KEV catalog, which may lead to it being overlooked by organizations that monitor that list.

Generated by OpenCVE AI on August 4, 2026 at 13:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all affected cameras to firmware HC5.26.1.16.20260207
  • Restrict or disable remote management interfaces so that only authorized users can access the camera’s administrative functions
  • Configure network segmentation or firewall rules to prevent external networks from reaching the camera’s management ports, ensuring audit logs remain accessible only within trusted internal segments

Generated by OpenCVE AI on August 4, 2026 at 13:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Honeywell
Honeywell s35 Camera
Vendors & Products Honeywell
Honeywell s35 Camera

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14.20260207 contains an audit log disclosure Vulnerability that could allow an attacker to access audit logs without authentication, potentially resulting in the disclosure of sensitive information. Honeywell recommends updating to the latest available version (HC5.26.1.16.20260207) once available.
Title Audit Log Exposure through Unauthorized Access
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Honeywell S35 Camera
cve-icon MITRE

Status: PUBLISHED

Assigner: Honeywell

Published:

Updated: 2026-07-27T19:37:40.824Z

Reserved: 2026-07-27T18:45:08.664Z

Link: CVE-2026-17612

cve-icon Vulnrichment

Updated: 2026-07-27T19:37:36.893Z

cve-icon NVD

Status : Received

Published: 2026-07-27T19:17:15.770

Modified: 2026-07-27T20:16:39.497

Link: CVE-2026-17612

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T14:00:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor