CVE-2026-51134
The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameter in show-movies.pml.
Does this matter?
A public exploit is published in Exploit-DB and the impact is high, while EPSS rates exploitation at 1.9%. Anyone can run this; patch or mitigate before the next change window and check exposed instances for signs of use.
Description
The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameter in show-movies.pml.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.89% probability · 79th percentile
- Public exploits
- 1 in Exploit-DB · first 31 August 2026
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Source
- cve@mitre.org
EPSS 1.9% since 19 September 2026; no change recorded yet. Points are recorded when the score first appears and whenever it moves by a percentage point or more.
Public exploits (1)
Entries in Exploit-DB that cite this CVE. Links go to the Exploit-DB page and to the file in the public repository; nothing is hosted here. A verified tick means the Exploit-DB team confirmed the exploit works against the stated version.
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA, exploits from Exploit-DB. Refreshed daily. Download this record as JSON.