CVE-2026-100906

A vulnerability was detected in Eyeplus 57.0.0.0308. The affected element is the function GetUsers of the file /onvif/Device of the component ONVIF. The manipulation results in information disclosure. The attack can be executed remotely. The exploit is now public and may be used.

  • Published Sep 28, 2026
  • CVSS 5.5 medium
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-100906 at the National Vulnerability Database