CVE-2026-76060
OS Command Injection in PayRange API
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server.
| CWE | CWE-78 |
| Vendor | zoneminder |
| Product | zoneminder |
| Published | Aug 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for zoneminder zoneminder
Be the first to know when new high vulnerabilities affecting zoneminder zoneminder are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Zoneminder / Zoneminder
1.37.48 < 1.38.3
References
zoneminder.com: https://zoneminder.com/downloads github.com: https://github.com/ZoneMinder/zoneminder github.com: https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-88m4-hrgp-m9v3 cisa.gov: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-02 github.com: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-02.json
Credits
CISA discovered a public proof of concept (PoC) as authored by Scriptkittens and reported it to Zoneminder.