DoseFix LIVE
0votes
Security·United States·CONFIRMED

CISA Advisory: OS Command Injection Vulnerability in ZoneMinder (CVE-2026-76060)

United States·
DoseFix EditorialMulti-source synthesis

CISA released a cybersecurity advisory on August 25, 2026, detailing a high-severity vulnerability (CVE-2026-76060) in ZoneMinder, an open-source video surveillance software. The vulnerability is an authenticated OS command injection in the event export functionality, where the 'exportFile' HTTP parameter is passed unsanitized into a shell command executed via PHP's exec(). An authenticated user with 'View Events' permission can execute arbitrary operating system commands on the server, potentially leading to full remote code execution as the web server user. Affected versions are ZoneMinder 1.37.48 and 1.38.3. The CVSS base score is 8.8 (High) under CVSS v3.1 and 8.7 under v4.0. CISA discovered a public proof-of-concept authored by 'Scriptkittens' and reported it to ZoneMinder. The vendor recommends upgrading to version 1.38.3 or later. No known public exploitation has been reported to CISA at this time. CISA advises users to minimize network exposure, use firewalls, and apply vendor patches.

1 sources
United States

What we know

Successful exploitation could result in full remote code execution as the web server user.

1 sources

The vulnerability is an authenticated OS command injection in ZoneMinder's event export functionality.

1 sources

No known public exploitation has been reported to CISA at this time.

1 sources

CISA discovered a public proof-of-concept authored by 'Scriptkittens'.

1 sources

CISA published an advisory on 2026-08-25 for CVE-2026-76060.

1 sources

CVSS v3.1 base score is 8.8 (High).

1 sources

ZoneMinder recommends upgrading to version 1.38.3 or later.

1 sources
Source transparency

Open any source to inspect its original language, when DoseFix received it, and the claims it supports.

CISA Cybersecurity Advisories

Zoneminder

cisa.gov · EN · Published · Received
Independent

Live reports

View all
Advisory TimelineLocal voice · United States
Verified

Comments 0

Discuss this event in persistent threads. Live chat remains separate.

Keep discussion civil and distinguish opinion from verified information.

No comments yet. Start the conversation.

CISA Advisory: OS Command Injection Vulnerability in ZoneMinder (CVE-2026-76060) | DoseFix