File System Vulnerability in ZimaOS by IceWhaleTech
CVE-2026-28286
What is CVE-2026-28286?
In ZimaOS version 1.5.2-beta3, a critical flaw allows unauthorized file creation in sensitive system directories through the API. Although frontend restrictions exist to prevent users from modifying internal OS paths, these safeguards do not extend to the API level, enabling a malicious actor to execute crafted requests that bypass these restrictions. This vulnerability allows for the creation of files or directories in critical areas like /etc and /usr, presenting a significant risk as the API fails to properly validate target paths. Currently, there are no publicly known patches to remediate this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ZimaOS = 1.5.2-beta3
