PatchSiren

OpenEye CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH OpenEye CVE published 2026-09-23

CVE-2026-94367

CVE-2026-94367 is an OS command injection vulnerability in OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376. An authenticated administrator can supply crafted backup-area configuration input that is passed to a shell command, allowing commands to execute with the privileges of the nvr user. The vulnerability is resolved in OpenEye Apex version 3.4.3.