CVE-2026-76060: Zoneminder
High severity, CVSS 8.8. EPSS: 2.4% chance of exploitation in the next 30 days.
An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server.
Affected products
- Zoneminder Zoneminder: from 1.37.48, before 1.38.3 (fixed in 1.38.3)
Published 2026-08-28. Last modified 2026-08-31.