Authentication Bypass Vulnerability in ZimaOS by IceWhaleTech
CVE-2026-21891

9.4CRITICAL

Key Information:

Status
Vendor
CVE Published:
8 January 2026

What is CVE-2026-21891?

ZimaOS, a modified version of CasaOS designed for specific Zima devices and x86-64 systems, contains a significant security flaw in its authentication mechanism. In affected versions up to 1.5.0, the application inadequately validates passwords when the input username corresponds to known system service accounts. This vulnerability allows malicious actors to gain unauthorized access simply by providing a valid service account username and any password. As of the latest information, no patches are available to mitigate this issue, posing a risk to users relying on this operating system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

ZimaOS <= 1.5.0

References

CVSS V3.1

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.