IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Zoneminder

HIGH
CVSS 8.8
Date 2026-08-25T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could result in full Remote Code Execution (RCE) as the web server user.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-76060 8.8 high
An authenticated OS Command Injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server.

// Remediations (3)

Patch: For more details refer to Zoneminder's security advisories at: https://github.com/ZoneMinder/zonemin
For more details refer to Zoneminder's security advisories at: https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-88m4-hrgp-m9v3.
Patch: Zoneminder recommends upgrading to version 1.38.3 or later by downloading the installer for your sys
Zoneminder recommends upgrading to version 1.38.3 or later by downloading the installer for your system at: https://zoneminder.com/downloads.
Patch: Users may also get the source code from Zoneminder's Github: https://github.com/ZoneMinder/zoneminde
Users may also get the source code from Zoneminder's Github: https://github.com/ZoneMinder/zoneminder.

// References