Authentication Bypass Vulnerability in ZimaOS by IceWhaleTech
CVE-2026-21891
What is CVE-2026-21891?
ZimaOS, a modified version of CasaOS designed for specific Zima devices and x86-64 systems, contains a significant security flaw in its authentication mechanism. In affected versions up to 1.5.0, the application inadequately validates passwords when the input username corresponds to known system service accounts. This vulnerability allows malicious actors to gain unauthorized access simply by providing a valid service account username and any password. As of the latest information, no patches are available to mitigate this issue, posing a risk to users relying on this operating system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ZimaOS <= 1.5.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
