DoseFix LIVE
0votes
Security·United States·CONFIRMED

CISA Advisory: OS Command Injection Vulnerability in ZoneMinder (CVE-2026-76060)

United States·

CISA released a cybersecurity advisory on August 25, 2026, detailing a high-severity vulnerability (CVE-2026-76060) in ZoneMinder, an open-source video surveillance software. The vulnerability is an authenticated OS command injection in the event export functionality, where the 'exportFile' HTTP parameter is passed unsanitized into a shell command executed via PHP's exec(). An authenticated user with 'View Events' permission can execute arbitrary operating system commands on the server, potentially leading to full remote code execution as the web server user. Affected versions are ZoneMinder 1.37.48 and 1.38.3. The CVSS base score is 8.8 (High) under CVSS v3.1 and 8.7 under v4.0. CISA discovered a public proof-of-concept authored by 'Scriptkittens' and reported it to ZoneMinder. The vendor recommends upgrading to version 1.38.3 or later. No known public exploitation has been reported to CISA at this time. CISA advises users to minimize network exposure, use firewalls, and apply vendor patches.

1 sources
United States

What we know

Successful exploitation could result in full remote code execution as the web server user.

1 sources

The vulnerability is an authenticated OS command injection in ZoneMinder's event export functionality.

1 sources

No known public exploitation has been reported to CISA at this time.

1 sources

CISA discovered a public proof-of-concept authored by 'Scriptkittens'.

1 sources

CISA published an advisory on 2026-08-25 for CVE-2026-76060.

1 sources

CVSS v3.1 base score is 8.8 (High).

1 sources

ZoneMinder recommends upgrading to version 1.38.3 or later.

1 sources
Advisory Timeline

CISA published an advisory for an authenticated OS command injection vulnerability (CVE-2026-76060) in ZoneMinder versions 1.37.48 and 1.38.3, which could allow remote code execution as the web server user. The vendor recommends upgrading to 1.38.3 or later.

Verified · 1 sources

Live reports

View all
Advisory TimelineLocal voice · United States
Verified

Comments 0

Discuss this event in persistent threads. Live chat remains separate.

Keep discussion civil and distinguish opinion from verified information.

No comments yet. Start the conversation.