CVE-2026-76060
View CSAF Summary Successful exploitation of this vulnerability could result in full Remote Code Execution (RCE) as the web server user. The following versions of Zoneminder are affected: Zoneminder 1.37.48|1.38.3 CVSS Vendor Equipment Vulnerabilities v3 8.8 Zoneminder Zoneminder Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Background Critical Infrastructure Sectors: Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-76060 An authenticated OS Command Injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server. View CVE Details Affected Products Zoneminder Vendor: Zoneminder Product Version: Zoneminder Zoneminder: 1.37.48|1.38.3 Product Status: known_affected Remediations Vendor fix Zoneminder recommends upgrading to version 1.38.3 or later by downloading the installer for your system at: https://zoneminder.com/downloads. https://zoneminder.com/downloads Vendor fix Users may also get the source code from Zoneminder's Github: https://github.com/ZoneMinder/zoneminder. https://github.com/ZoneMinder/zoneminder Vendor fix For more details refer to Zoneminder's security advisories at: https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-88m4-hrgp-m9v3. https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-88m4-hrgp-m9v3 Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments CISA discovered a public Proof of Conc
CSIRTS triage
- What
- An authenticated OS command injection vulnerability in the event export functionality allows arbitrary shell command execution through the unsanitized exportFile parameter.
- Who is affected
- Zoneminder 1.37.48 and 1.38.3 deployments with authenticated users having View Events permission.
- Urgency
- Critical; authenticated remote code execution as the web server user allows full system compromise.
- Action
- Update Zoneminder to a patched version beyond 1.38.3 that sanitizes the exportFile parameter.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-76060
Get an email if CVE-2026-76060 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Advisory coverage (1)
- criticalZonemindercisa · 2026-08-25
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-76060)