Skip to content
Threat Feed
high advisory

Pelco Sarix Pro 3 Series IP Camera Authentication Bypass Vulnerability

An authentication bypass vulnerability (CVE-2026-1241) in the web management interface of Pelco Sarix Pro 3 Series IP Cameras (versions <= 02.52) allows unauthenticated attackers to access sensitive device data and bypass surveillance controls.

Pelco Sarix Pro 3 Series IP Cameras are affected by an authentication bypass vulnerability (CVE-2026-1241) in their web management interface. The vulnerability stems from inadequate access control enforcement, allowing unauthorized access to certain functionalities without proper authentication. This issue impacts Sarix Professional IMP 3 Series, IXP 3 Series, IBP 3 Series, and IWP 3 Series IP Cameras with firmware versions equal to or less than 02.52. Successful exploitation can lead to…

Detection coverage 2

Detect Unauthorized Access to Pelco Sarix Camera Web Interface

medium

Detects unauthorized attempts to access the web interface of Pelco Sarix IP cameras, potentially indicating exploitation of CVE-2026-1241.

sigma tactics: initial_access techniques: T1190 sources: network_connection, windows

Detect Configuration Changes on Pelco Sarix Cameras

medium

Detects suspicious changes to camera configuration settings via the web interface, potentially indicating unauthorized access.

sigma tactics: persistence techniques: T1547.001 sources: network_connection, windows

Detection queries are kept inside the platform. Get full rules →