---
id: CVE-2026-92838
title: "A DLL hijacking\nvulnerability exists in the GeoVision\_GV-Remote E-Map\_desktop\napplication"
summary: "A DLL hijacking\nvulnerability exists in the GeoVision\_GV-Remote E-Map\_desktop\napplication. The application loads one or more dynamic-link libraries (DLLs)\nfrom an unsafe search path, allowing a local attacker to place a malicious DLL\nin …"
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-427
vendor: GeoVision Inc.
product: GV-Remote E-map
affected:
  - gv-remote_e-map V18.3.1
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:41:42.593'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92838'
references:
  - url: 'https://hackerone.com/reports/1437942'
    label: 0df08a0e-a200-4957-9bb0-084f562506f9
  - url: 'https://www.cve.org/CVERecord?id=CVE-2020-26947'
    label: 0df08a0e-a200-4957-9bb0-084f562506f9
  - url: 'https://www.geovision.com.tw/cyber_security.php'
    label: 0df08a0e-a200-4957-9bb0-084f562506f9
tags:
  - nvd
  - cve.org
epss: 0.00198
epssPercentile: 0.08569
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T13:00:33.907550Z'
ingestedAt: '2026-09-17T02:09:26.491Z'
---

## Overview

A DLL hijacking
vulnerability exists in the GeoVision GV-Remote E-Map desktop
application. The application loads one or more dynamic-link libraries (DLLs)
from an unsafe search path, allowing a local attacker to place a malicious DLL
in a location searched before the legitimate library location. If
successfully exploited, an attacker with local write access to the affected
directory could achieve arbitrary code execution in the security context of
the GV-Remote E-Map process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
