Zoneminder
View CSAF Summary Successful exploitation of this vulnerability could result in full Remote Code Execution (RCE) as the web server user. The following versions of Zoneminder are affected: Zoneminder 1.37.48|1.38.3 CVSS Vendor Equipment Vulnerabilities v3 8.8 Zoneminder Zoneminder Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Background Critical Infrastructure Sectors: Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-76060 An authenticated OS Command Injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server. View CVE Details Affected Products Zoneminder Vendor: Zoneminder Product Version: Zoneminder Zoneminder: 1.37.48|1.38.3 Product Status: known_affected Remediations Vendor fix Zoneminder recommends upgrading to version 1.38.3 or later by downloading the installer for your system at: https://zoneminder.com/downloads. https://zoneminder.com/downloads Vendor fix Users may also get the source code from Zoneminder's Github: https://github.com/ZoneMinder/zoneminder. https://github.com/ZoneMinder/zoneminder Vendor fix For more details refer to Zoneminder's security advisories at: https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-88m4-hrgp-m9v3. https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-88m4-hrgp-m9v3 Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments CISA discovered a public Proof of Conc
CSIRTS triage
- What
- An authenticated OS command injection vulnerability in the event export functionality allows arbitrary shell command execution through the unsanitized exportFile parameter.
- Who is affected
- Zoneminder 1.37.48 and 1.38.3 deployments with authenticated users having View Events permission.
- Urgency
- Critical; authenticated remote code execution as the web server user allows full system compromise.
- Action
- Update Zoneminder to a patched version beyond 1.38.3 that sanitizes the exportFile parameter.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Zoneminder
Get an email when a new Zoneminder advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-02
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-76060 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Zoneminder
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
More from CISA Cybersecurity Advisories
- criticalA Tale of Two SOCs: Insights From Two Red Team Assessments2026-08-25
- criticalSiemens SIMATIC IoT2050 Advanced2026-08-25
- criticalFURUNO FA-50 Class B AIS Transponder2026-08-25
- criticalBendix EC80 Brake ECU2026-08-25
- criticalEbyte NE2-D112026-08-25