CVE-2026-17612: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor in Honeywell S35 Series 3M/5M/8M/PinHole Cameras
Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14.20260207 contains an audit log disclosure Vulnerability that could allow an attacker to access audit logs without authentication, potentially resulting in the disclosure of sensitive information. Honeywell recommends updating to the latest available version (HC5.26.1.16.20260207) once available.
AI Analysis
Technical Summary
CVE-2026-17612 describes an audit log disclosure vulnerability in Honeywell S35 Series 3M/5M/8M/PinHole Cameras, allowing unauthenticated attackers to access audit logs and potentially sensitive information. The vulnerability affects all versions up to and including HC5.26.1.14.20260207. Honeywell recommends updating to version HC5.26.1.16.20260207 once available. The product is cloud-hosted, and remediation is managed by Honeywell. The CVSS 4.0 vector indicates network attack vector, low complexity, no privileges or user interaction required, and low confidentiality impact.
Potential Impact
An attacker can access audit logs without authentication, which may lead to disclosure of sensitive information contained in those logs. This exposure could aid attackers in further reconnaissance or exploitation but does not directly allow system compromise or denial of service.
Mitigation Recommendations
Honeywell manages remediation for this cloud-hosted service. Users should verify with Honeywell that their devices are updated to version HC5.26.1.16.20260207 or later to address this vulnerability. Patch status is confirmed as available. No additional mitigation actions are specified by the vendor.
CVE-2026-17612: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor in Honeywell S35 Series 3M/5M/8M/PinHole Cameras
Description
Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14.20260207 contains an audit log disclosure Vulnerability that could allow an attacker to access audit logs without authentication, potentially resulting in the disclosure of sensitive information. Honeywell recommends updating to the latest available version (HC5.26.1.16.20260207) once available.
CVSS v4.0
Score 6.9medium
Affected software
Honeywell
S35 Series 3M/5M/8M/PinHole Cameras
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-17612 describes an audit log disclosure vulnerability in Honeywell S35 Series 3M/5M/8M/PinHole Cameras, allowing unauthenticated attackers to access audit logs and potentially sensitive information. The vulnerability affects all versions up to and including HC5.26.1.14.20260207. Honeywell recommends updating to version HC5.26.1.16.20260207 once available. The product is cloud-hosted, and remediation is managed by Honeywell. The CVSS 4.0 vector indicates network attack vector, low complexity, no privileges or user interaction required, and low confidentiality impact.
Potential Impact
An attacker can access audit logs without authentication, which may lead to disclosure of sensitive information contained in those logs. This exposure could aid attackers in further reconnaissance or exploitation but does not directly allow system compromise or denial of service.
Mitigation Recommendations
Honeywell manages remediation for this cloud-hosted service. Users should verify with Honeywell that their devices are updated to version HC5.26.1.16.20260207 or later to address this vulnerability. Patch status is confirmed as available. No additional mitigation actions are specified by the vendor.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Honeywell
- Date Reserved
- 2026-07-27T18:45:08.664Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Is Cloud Service
- true
Threat ID: 6a67b0129c2644c7f8ad2d1c
Added to database: 07/27/2026, 19:22:58 UTC
Last enriched: 07/30/2026, 00:59:53 UTC
Last updated: 09/10/2026, 20:02:43 UTC
Views: 85
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.