CVE-2026-4606Disclosure

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

GV Edge Recording Manager (ERM) v2.3.1 improperly runs application components with SYSTEM-level privileges, allowing any local user to gain full control of the operating system.  During installation, ERM creates a Windows service that runs under the LocalSystem account.  When the ERM application is launched, related processes are spawned under SYSTEM privileges rather than the security context of the logged-in user.  Functions such as 'Import Data' open a Windows file dialog operating with SYSTEM permissions, enabling modification or deletion of protected system files and directories.  Any ERM function invoking Windows file open/save dialogs exposes the same risk.  This vulnerability allows local privilege escalation and may result in full system compromise.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-250

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 5 mentions (2026-03-23); latest day: 1
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01345Mentions · 2026-03-23: 5Mentions · 2026-03-24: 1Mentions · 2026-03-25: 1PoC Mentioned / Linked · 2026-03-23: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-25: 1Technical Details · 2026-03-23: 5Technical Details · 2026-03-24: 1Technical Details · 2026-03-25: 103-2303-2403-25
Signal classification3 categories
Disclosure
342.9%
General
228.6%
Patch
228.6%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-235
Disclosure2General2Patch1
2026-03-241
Disclosure1
2026-03-251
Patch1
Full discourse7 posts
  • Gray Hats@the_yellow_fall
    Patch

    GeoVision fixes a critical 10.0 CVSS flaw in GV-Edge Recording Manager. CVE-2026-4606 allows local users to gain SYSTEM-level control. Update to V2.3.2 now. #GeoVision #CyberSecurity #CVE #InfoSec #PrivilegeEscalation #PatchAlert #Surveillance https://securityonline.info/geovision-erm-critical-vulnerability-cve-2026-4606-system-privilege-escalation/ https://t.co/aRyPnbEaeD

    Post summary

    The post announces that GeoVision has released V2.3.2 to address the critical CVE‑2026‑4606 vulnerability, which allows local users to gain SYSTEM-level control.

    04071523
    10.9K followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-4606 | CVSS 10.0 🔴 CVE-2026-3587 | CVSS 10.0 🔴 CVE-2026-4567 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post enumerates three CVEs with high CVSS scores and directs readers to a link for more information, but it provides no specific details on exploits, patches, or active attacks.

    0001071
    5.6K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4606 📊 Severity: 10.0 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4606 #CVE-2026-4606 #CVE #Critical  #CyberSecurity #InfoSec https://t.co/5LiI7qf4Yp

    Post summary

    The tweet announces the new CVE‑2026‑4606 with a CVSS 10.0 critical score, providing only a link to the NVD entry and no further exploit or mitigation details.

    0000026
    111 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical vulnerability in #GeoVision #GV-Edge Recording Manager. CVE-2026-4606. Local users can exploit this vulnerability to execute arbitrary code as the system user and elevate their privileges. More info: https://dlcdn.geovision.com.tw/TechNotice/CyberSecurity/2026/Security_Advistory_GV-ERM-2026-03-01.pdf #Patch #Patch #Patch

    Post summary

    The GeoVision technical advisory warns of a critical local privilege escalation flaw (CVE‑2026‑4606) in GV‑Edge Recording Manager and points to a PDF containing patch and mitigation details.

    00000238
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4606 GV Edge Recording Manager (ERM) v2.3.1 improperly runs application components with SYSTEM-level privileges, allowing any local user to gain full control of the operatin… https://www.cve.org/CVERecord?id=CVE-2026-4606

    Post summary

    The snippet announces a local privilege escalation issue in GV Edge Recording Manager v2.3.1, where SYSTEM‑level execution allows local users full control, but it lacks proof‑of‑concept, exploit, patch details or evidence of active exploitation.

    0000097
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4606 - GeoVision ERM Improper Privilege Assignment Leads to SYSTEM-Level Privilege Intel Report: https://ift.tt/X920r1j

    Post summary

    The alert announces CVE‑2026‑4606 as an improper privilege assignment flaw that could elevate privileges to system level, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    0000034
    289 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-4606: GeoVi... GeoVision ERM's file dialogs run as SYSTEM - trivial local privesc via Import Data function spawns SYSTEM-privileged explorer.exe #PrivEsc #Windows. https://zerodaysignal.com/vulnerability/CVE-2026-4606 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    GeoVision ERM’s Import Data function runs file dialogs as SYSTEM, enabling a trivial local privilege escalation that spawns SYSTEM‑privileged explorer.exe (CVE‑2026‑4606); detailed information and a possible PoC are available via the linked ZeroDaySignal page.

    0000063
    162 followersView on X

Explore more