
Dahua CVE-2026-29114
Advisory type: Vendor-coordinated security disclosure
CVE ID: CVE-2026-29114
Vendor: Dahua Technology
Published: 2026-06-10T05:44:50 UTC
Last Modified: 2026-06-10T05:44:50 UTC
Source: Dahua Product Security Incident (PSI) Trust Center
A low-severity certificate-trust vulnerability has been identified in select Dahua IPC (IP camera) models. Under certain deployment conditions, a remote attacker can obtain the device's internal CA root certificate — material that should remain private to the certificate authority hierarchy.
If that root CA (or an intermediate derived from it) has been installed and trusted on client workstations, browsers, or middleware, an attacker who possesses the private key material can mint fraudulent X.509 certificates that validating clients will accept as legitimate. That enables person-in-the-middle (MITM) attacks against HTTPS or TLS-protected sessions that chain to the compromised trust anchor, undermining the confidentiality and integrity of affected client connections.
The published CVSS 4.0 base score is 2.3 (LOW). The relatively low score reflects deployment preconditions (AT:P — attack requirements present) and passive user interaction (UI:P) needed for practical impact, plus Low (not High) direct confidentiality and integrity ratings on the vulnerable device itself. Availability is not impacted (VA:N).
Organizations running affected IPC firmware builds before April 15, 2026 should verify whether device-issued CAs were ever distributed to endpoints, remove untrusted roots from client trust stores, rotate TLS configurations, and upgrade firmware.
Note on advisory labeling: Some indexes title this CVE "Dahua Data Breach." The vendor description concerns exposure of a device CA root certificate and downstream PKI trust abuse — not bulk exfiltration of recorded video or customer databases. This document follows the vendor description and CVSS scoring data.
| Field | Value |
|---|---|
| CVE ID | CVE-2026-29114 |
| Vendor | Dahua Technology |
| Vulnerability Type | Sensitive certificate material exposure / trust-chain abuse |
| Attack Vector | Network |
| Authentication Required | No |
| User Interaction Required | Passive (UI:P) |
| Attack Requirements | Present (AT:P) |
| Privileges Required | None |
| CVSS Version | 4.0 |
| CVSS Base Score | 2.3 — LOW |
| CVSS Vector | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
| CWE | CWE-538 (Insertion of Sensitive Information into Externally-Accessible File or Directory) |
| Remotely Exploitable | Yes |
| Published Date | 2026-06-10 |
| Fix Availability | Firmware builds from April 15, 2026 onward (per vendor guidance) |
CVE-2026-29114 was published on 2026-06-10 alongside other Dahua PSI disclosures from the same batch. The issues are distinct in mechanism and impact profile.
| Attribute | CVE-2026-29114 (this advisory) | CVE-2026-29115 | CVE-2026-29116 |
|---|---|---|---|
| CVSS 4.0 Score | 2.3 — LOW | 6.9 — MEDIUM | 8.7 — HIGH |
| Primary Impact | Confidentiality + Integrity (Low) | Availability (High) | Availability (High) |
| Authentication | Not required | High privileges required | Not required |
| Affected Products | IPC only | IPC, SD | IPC, SD, NVR, XVR, EVS, VTO, VTH, ASI, TPC |
| Fix Build Cutoff | Before 2026-04-15 | Before 2026-03-26 | Before 2026-03-26 |
| CWE | CWE-538 | CWE-617 | CWE-617 |
| Published (UTC) | 2026-06-10T05:44:50 | 2026-06-10T06:08:21 | 2026-06-10T06:16:34 |
Defender takeaway: This CVE is not a camera reboot flaw. It is a PKI hygiene and trust-store problem. Patching matters, but removing improperly trusted device CAs from client machines is often the decisive remediation step.
| Date | Event |
|---|---|
| ≤ 2026-04-15 | Vulnerable IPC firmware builds in active distribution |
| 2026-04-15 | Vendor fix cutoff — builds produced on or after this date are outside the affected range (per advisory) |
| 2026-06-10T05:44:50 UTC | CVE-2026-29114 published |
| 2026-06-10T05:44:50 UTC | NVD record last modified |
| 2026-06-10 | Related CVE-2026-29115 and CVE-2026-29116 published later same day |
| Ongoing | Operators should audit trust stores and IPC firmware build dates |
Dahua has reported a vulnerability in some IPC models whereby sensitive certificate authority (CA) material associated with the device can be obtained by a remote party. The vendor states that an attacker may obtain the device's CA root certificate.
X.509 PKI security depends on private keys staying secret and trust anchors being deliberately chosen. If:
then an attacker can:
Per the published vector:
SC:N, SI:N, SA:N)Practical harm often manifests on client systems that trust the exposed CA, which is why attack requirements and user interaction metrics are elevated in the scoring model.
Many embedded devices ship with factory or firmware-bundled PKI to support: