---
id: CVE-2026-88622
title: >-
  NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in
  handle_import_privilege.php.
summary: >-
  NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in
  handle_import_privilege.php.
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-77
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T15:17:17.453'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88622'
references:
  - url: 'http://nuuo.com'
    label: cve@mitre.org
  - url: 'https://gist.github.com/4o3-f0rb1dd3n/b03b435a7c6730a0c9586bcc7967d9b5'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-18T14:23:43.499100Z'
ingestedAt: '2026-09-18T14:43:13.055Z'
epss: 0.01086
epssPercentile: 0.63349
---

## Overview

NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
