SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityReceived

CVE-2026-51134

The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameter in show-movies.pml.

EXPLOITHIGH 7.5EPSS 1.89%

Does this matter?

A public exploit is published in Exploit-DB and the impact is high, while EPSS rates exploitation at 1.9%. Anyone can run this; patch or mitigate before the next change window and check exposed instances for signs of use.

Description

The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameter in show-movies.pml.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
1.89% probability · 79th percentile
Public exploits
1 in Exploit-DB · first 31 August 2026
CISA KEV
Not listed
Weakness
CWE-22
Source
cve@mitre.org
EPSS trend
0%3%5%19 September 2026: 1.89%19 September 202619 September 2026

EPSS 1.9% since 19 September 2026; no change recorded yet. Points are recorded when the score first appears and whenever it moves by a percentage point or more.

Public exploits (1)

Entries in Exploit-DB that cite this CVE. Links go to the Exploit-DB page and to the file in the public repository; nothing is hosted here. A verified tick means the Exploit-DB team confirmed the exploit works against the stated version.

EDB-IDTitleTypePublishedVerified
EDB-52666source ↗C-MOR 6.0104 - Directory Traversalmultiple · Samir Shamdinwebapps31 August 2026no

Source: NVD record, EPSS from FIRST.org, KEV from CISA, exploits from Exploit-DB. Refreshed daily. Download this record as JSON.