Security & Threat Intelligence · 25.08.2026, 19:47 UTC
Zoneminder
| Schweregrad | info |
|---|---|
| CVE | ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA Advisories ↗ |
| Veröffentlicht | 25.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-76060. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary Successful exploitation of this vulnerability could result in full Remote Code Execution (RCE) as the web server user. The following versions of Zoneminder are affected:
Zoneminder 1.37.48|1.38.3
CVSS Vendor Equipment Vulnerabilities
v3 8.8 Zoneminder Zoneminder Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Background
Critical Infrastructure Sectors: Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-76060
An authenticated OS Command Injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server. View CVE Details
Affected Products Zoneminder
Vendor:Zoneminder Product Version:Zoneminder Zoneminder: 1.37.48|1.38.3 Product Status:known_affected
Remediations Vendor fixZoneminder recommends upgrading to version 1.38.3 or later by downloading the installer for your system at: https://zoneminder.com/downloads.https://zoneminder.com/downloads Vendor fixUsers may also get the source code from Zoneminder's Github: https://github.com/ZoneMinder/zoneminder.https://github.com/ZoneMinder/zoneminder Vendor fixFor more details refer to Zoneminder's security advisories at: …