CVE-2026-76060

Source
https://cve.org/CVERecord?id=CVE-2026-76060
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76060.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-76060
Aliases
  • GHSA-88m4-hrgp-m9v3
Published
2026-08-27T20:29:05.262Z
Modified
2026-08-30T03:31:05.047442182Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
OS Command Injection in PayRange API
Details

An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76060.json",
    "cwe_ids": [
        "CWE-78"
    ],
    "cna_assigner": "icscert"
}
References

Affected packages

Git / github.com/zoneminder/zoneminder

Affected ranges

Type
GIT
Repo
https://github.com/zoneminder/zoneminder
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "1.37.48"
        },
        {
            "fixed": "1.38.3"
        }
    ]
}

Affected versions

1.*
1.32.3
1.34.0
1.36.0
1.38.0
1.38.1
1.38.2
v1.*
v1.25
v1.26.0
v1.26.1
v1.26.2
v1.26.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-76060.json"