CVE-CVE-2026-76060
Severity
HIGH
CVSS Score
8.8
Description
An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server....
PoCs for CVE-CVE-2026-76060
CVE-2026-76060_ZoneMinder_CommandInjection-PoC
RCE
Python
1
investigato
2026-06-06