HIGH 8.7 NVD
CVE-2026-76060
An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitiz
An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server.
References
- https://github.com/ZoneMinder/zoneminder
- https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-88m4-hrgp-m9v3
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-02.json
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-02
- https://zoneminder.com/downloads
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-08-28 via NVD.
vulnfeed aggregates 11380 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.