Description
Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one appliances (SV-100E and SV-300E series) and Synergis Softwire installed on Windows servers.
Published: 2026-08-27
Score: 7.9 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper access control on the Synergis Softwire installation folder allows an attacker to read, modify, or delete critical configuration files. This lack of permission checks can enable privilege escalation, arbitrary code execution, or disruption of the Streamvault all‑in‑one appliance’s operation. The flaw is classified as CWE‑922, indicating unchecked file access vulnerability.

Affected Systems

The vulnerability affects Genetec Inc.’s Synergis Softwire installations, including the Streamvault all‑in‑one appliances such as the SV‑100E and SV‑300E series and deployments on Windows servers. Fixed versions are identified by Genetec in their 12.0.2 and 12.2.0 advisories, but explicit affected versions for the flaw are not listed in the public data.

Risk and Exploitability

With a CVSS score of 7.9 the flaw is considered high severity, offering significant impact if exploited. The EPSS score is unavailable, so the likelihood of exploitation is unknown, though the lack of directory restrictions makes the attack path straightforward for anyone who can locate or reach the installation folder. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed active exploitation as of now.

Generated by OpenCVE AI on August 28, 2026 at 06:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Genetec Security Update for Synergis Softwire as referenced by the vendor advisories
  • Secure the installation folder permissions so that only the required service account has read/write access
  • Disable network sharing or remove local user rights to the installation folder to prevent remote or local unauthorized access

Generated by OpenCVE AI on August 28, 2026 at 06:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control to Synergis Softwire Installation Folder

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one appliances (SV-100E and SV-300E series) and Synergis Softwire installed on Windows servers.
Weaknesses CWE-922
References
Metrics cvssV3_1

{'score': 7.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Genetec

Published:

Updated: 2026-08-27T22:08:52.736Z

Reserved: 2026-05-11T18:46:18.567Z

Link: CVE-2026-44629

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T00:17:28.117

Modified: 2026-08-28T00:17:28.117

Link: CVE-2026-44629

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T06:30:18Z

Weaknesses
  • CWE-922

    Insecure Storage of Sensitive Information