High severity8.8NVD Advisory· Published Aug 28, 2026· Updated Aug 31, 2026
CVE-2026-76060
CVE-2026-76060
Description
An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
1- ZoneminderCISA ICS Advisories