Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-76060

HIGH NVD
CVSS Score 8.8
Severity HIGH
Published Aug 28, 2026
Vendor unknown

Description

An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server.

References