boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-94367

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup.
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0103   62.3     —
AFFECTED
  Product                            Versions     Fixed
  Apex Network Video Recorder (NVR)  3.2.9.376 –  3.4.3
TIMELINE
  Sep 21  Reserved by Securifera
  Sep 22  Published (CNA: Securifera)
  Sep 26  PATCH SHIPPED — CVE-2026-94367 (OpenEye Apex Network Video Recorder (NVR)). Fixed in Apex Network Video Recorder (NVR) 3.4.3.
CWE-78 · CNA: Securifera · CVSS v3.1 · 2 references · NVD status: Deferred

Description

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup. An authenticated administrator can supply crafted backup-area configuration input that is passed to a shell command, allowing commands to execute with the privileges of the nvr user. The underlying design has been present since at least firmware 2.2.3.4. This vulnerability is resolved in OpenEye Apex version 3.4.3.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
September 21, 2026ReservedReserved by Securifera
September 22, 2026PublishedPublished (CNA: Securifera)
September 26, 2026PATCH SHIPPEDPATCH SHIPPED — CVE-2026-94367 (OpenEye Apex Network Video Recorder (NVR)). Fixed in Apex Network Video Recorder (NVR) 3.4.3.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
OpenEyeApex Network Video Recorder (NVR)—3.2.9.3763.4.3

Weaknesses

CWE-78

References (2)

Related

Authoritative record: CVE-2026-94367 at cve.org

Vendors: openeye

Weaknesses: CWE-78

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-94367 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.