OS Command Injection Vulnerability in ZoneMinder
CVE-2026-76060

8.7HIGH

Key Information:

Vendor

Zoneminder

Vendor
CVE Published:
27 August 2026

What is CVE-2026-76060?

An OS command injection vulnerability exists in ZoneMinder's event export functionality, where the exportFile HTTP request parameter is improperly sanitized before being used in a shell command via PHP's exec() function. This flaw allows any authenticated user with 'View Events' permission to execute arbitrary commands on the server, potentially leading to severe security breaches and unauthorized access to sensitive data.

Affected Version(s)

Zoneminder 1.37.48 < 1.38.3

Zoneminder 1.38.3

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CISA discovered a public proof of concept (PoC) as authored by Scriptkittens and reported it to Zoneminder.
.