Zoneminder

Plan PatchCVSS 8.8ICS-CERT ICSA-26-237-02Aug 25, 2026
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Zoneminder versions 1.37.48 and 1.38.3 contain an OS command injection vulnerability (CWE-78) that allows authenticated users to execute arbitrary commands on the server with the privileges of the web server process. This results in full Remote Code Execution as the web server user. The vulnerability is exploitable over the network without user interaction.

What this means
What could happen
An attacker with user-level web access could run arbitrary commands on your Zoneminder server with the permissions of the web server process, allowing them to access recorded video, modify system configurations, or disrupt video surveillance operations.
Who's at risk
Organizations using Zoneminder for IP camera surveillance and video recording, including water utilities and electric utilities with security monitoring systems. Any facility relying on Zoneminder for physical security or infrastructure monitoring should prioritize this update.
How it could be exploited
An attacker with valid login credentials to the Zoneminder web interface can exploit this vulnerability to execute arbitrary commands on the server. The attacker supplies malicious input through the web application, which is processed by the server without proper sanitization, allowing command injection.
Prerequisites
  • Valid Zoneminder web interface credentials
  • Network access to the Zoneminder web server (typically port 8080 or 80/443)
remotely exploitablelow complexityhigh CVSS score (8.8)OS command injection (CWE-78)
Exploitability
Some exploitation risk — EPSS score 2.3%
Public Proof-of-Concept (PoC) on GitHub (1 repository)
Affected products (1)
ProductAffected VersionsFix Status
Zoneminder: 1.37.48|1.38.31.37.48|1.38.3Fix available
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Zoneminder to version 1.38.3 or later
API: /api/v1/advisories/fb967e75-20db-4d7f-a5f0-d98cfe147aed

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Zoneminder | CVSS 8.8 - OTPulse