CVE-2026-28442

Source
https://cve.org/CVERecord?id=CVE-2026-28442
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-28442.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-28442
Aliases
  • GHSA-q5hp-59wm-9xq3
Published
2026-03-05T20:38:37.475Z
Modified
2026-03-14T13:51:43.909753Z
Severity
  • 8.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
ZimaOS: Arbitrary Deletion of Internal System Files via API Path Manipulation
Details

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, users are restricted from deleting internal system files or folders through the application interface. However, when interacting directly with the API, these restrictions can be bypassed. By altering the path parameter in the delete request, internal OS files and directories can be removed successfully. The backend processes these manipulated requests without validating whether the targeted path belongs to restricted system locations. This demonstrates improper input validation and broken access control on sensitive filesystem operations. No known public patch is available.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-73"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28442.json"
}
References

Affected packages

Git / github.com/icewhaletech/zimaos

Affected ranges

Type
GIT
Repo
https://github.com/icewhaletech/zimaos
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "= 1.5.2-beta3"
        }
    ]
}

Affected versions

0.*
0.4.8
0.4.8.1
0.4.9
0.4.9.1
0.4.9.2
0.4.9.3
0.4.9.4
0.5.0
1.*
1.0.0
1.1.0
1.2.2
1.2.3
1.2.3-beta1
1.2.4
1.2.4-beta1
1.2.4-beta2
1.2.5
1.2.5-beta1
1.2.5-beta2
1.2.5-beta3
1.3.0
1.3.0-1
1.3.0-2
1.3.0-beta1
1.3.1
1.3.1-1
1.3.1-beta1
1.3.2
1.3.2-1
1.3.2-beta1
1.3.2-beta2
1.3.3
1.3.3-beta1
1.4.0
1.4.0-beta1
1.4.0-beta2
1.4.1
1.4.1-beta1
1.4.1-beta2
1.4.2
1.4.2-beta1
1.4.2-beta2
1.4.3
1.4.4
1.4.4-1
1.4.4-beta1
1.5.0
1.5.0-beta1
1.5.1
1.5.1-beta1
1.5.2-beta1
1.5.2-beta2
1.5.2-beta3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-28442.json"