---
cve: "CVE-2026-8598"
severity: "CRITICAL"
cvss: 9.1
epss: "0.5%"
vendor: "ZKTeco"
kev: false
exploited: false
published: "2026-05-20 16:16:27"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-21T08:13:17+02:00"
---

# CVE-2026-8598

> 9.1 CRITICAL · 🧪 PoC

## Beschreibung

An undocumented configuration export port is accessible on some models 
of ZKTeco CCTV cameras. This port does not require authentication and 
exposes critical information about the camera such as open services and 
camera account credentials.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Referenzen

- <https://www.zkteco.com/en/announcement/23>
- <https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-04>
- <https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-139-04.json>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-8598) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
