CVE-2026-88278

GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.

  • Published Sep 10, 2026
  • CVSS 9.8 critical
  • 0.5% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-88278 at the National Vulnerability Database