Vulnerability
Published 2026-09-17
Verified 2026-09-19

GeoVision GV-Remote E-Map DLL hijacking CVE-2026-92838 (CVSS 7.8)

CVE-2026-92838 (published ~17 September 2026 per Tenable) is a DLL hijacking issue in the GeoVision GV-Remote E-Map desktop application: one or more DLLs are loaded from an unsafe search path. A local attacker with write access to a directory searched before the legitimate library location can plant a malicious DLL and achieve code execution as the GV-Remote E-Map process. Tenable CVSS 3.1 base 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Vendor cyber-security portal (geovision.com.tw/cyber_security.php) hosts GeoVision advisories; this CVE id was not visible as a labelled row on that index during the 18 September 2026 07:00 Perth desk pass — treat Tenable/CVE record as primary until a matching PDF advisory is linked. No public in-the-wild exploitation claim on the Tenable snippet reviewed. Relevance: physical-security / VMS operators running GeoVision Windows clients.

Product
GeoVision GV-Remote E-Map (Windows desktop)
Versions
Affected builds not enumerated on the Tenable snippet reviewed; check GeoVision cyber_security.php / product release notes for the fixed package
CVSS
Exploited in Australia?
unknown
Patch to
Apply the vendor-fixed GV-Remote E-Map build when published; restrict write access to application and working directories; do not run the client from world-writable paths.

Primary: Tenable — CVE-2026-92838 GeoVision GV-Remote E-Map (17 Sep 2026) · Vendor: GeoVision — Cyber Security advisories portal · CVE: CVE-2026-92838 · CVE.org — CVE-2026-92838

vulnerabilities ot ics