CVE-2026-94367: Openeye Apex Network Video Recorder NVR

High severity, CVSS 7.2. EPSS: 1% chance of exploitation in the next 30 days.

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup. An authenticated administrator can supply crafted backup-area configuration input that is passed to a shell command, allowing commands to execute with the privileges of the nvr user. The underlying design has been present since at least firmware 2.2.3.4. This vulnerability is resolved in OpenEye Apex version 3.4.3.

Affected products

  • Openeye Apex Network Video Recorder NVR: version 3.2.9.376 only

Published 2026-09-23. Last modified 2026-09-26.