CISA Advisory: OS Command Injection Vulnerability in ZoneMinder (CVE-2026-76060)
CISA released a cybersecurity advisory on August 25, 2026, detailing a high-severity vulnerability (CVE-2026-76060) in ZoneMinder, an open-source video surveillance software. The vulnerability is an authenticated OS command injection in the event export functionality, where the 'exportFile' HTTP parameter is passed unsanitized into a shell command executed via PHP's exec(). An authenticated user with 'View Events' permission can execute arbitrary operating system commands on the server, potentially leading to full remote code execution as the web server user. Affected versions are ZoneMinder 1.37.48 and 1.38.3. The CVSS base score is 8.8 (High) under CVSS v3.1 and 8.7 under v4.0. CISA discovered a public proof-of-concept authored by 'Scriptkittens' and reported it to ZoneMinder. The vendor recommends upgrading to version 1.38.3 or later. No known public exploitation has been reported to CISA at this time. CISA advises users to minimize network exposure, use firewalls, and apply vendor patches.
What we know
Successful exploitation could result in full remote code execution as the web server user.
▤ 1 sources›
The vulnerability is an authenticated OS command injection in ZoneMinder's event export functionality.
▤ 1 sources›
No known public exploitation has been reported to CISA at this time.
▤ 1 sources›
CISA discovered a public proof-of-concept authored by 'Scriptkittens'.
▤ 1 sources›
CISA published an advisory on 2026-08-25 for CVE-2026-76060.
▤ 1 sources›
CVSS v3.1 base score is 8.8 (High).
▤ 1 sources›
ZoneMinder recommends upgrading to version 1.38.3 or later.
▤ 1 sources›
CISA published an advisory for an authenticated OS command injection vulnerability (CVE-2026-76060) in ZoneMinder versions 1.37.48 and 1.38.3, which could allow remote code execution as the web server user. The vendor recommends upgrading to 1.38.3 or later.
Verified · 1 sourcesLive reports
View allComments 0
Discuss this event in persistent threads. Live chat remains separate.
No comments yet. Start the conversation.