Upgrade ZoneMinder to version 1.38.3 or later immediately. Download the installer from https://zoneminder.com/downloads or obtain the source code from https://github.com/ZoneMinder/zoneminder. Apply the fix from security advisory GHSA-88m4-hrgp-m9v3. Restrict user permissions to limit the number of authenticated users with View Events access. Monitor for suspicious activity in web server logs.
Quick answers
What is CVE-2026-76060?
Upgrade ZoneMinder to version 1.38.3 or later immediately. Download the installer from https://zoneminder.com/downloads or obtain the source code from https://github.com/ZoneMinder/zoneminder. Apply the fix from security advisory GHSA-88m4-hrgp-m9v3. Restrict user permissions to limit the number of authenticated users with View Events access. Monitor for suspicious activity in web server logs.
How severe is CVE-2026-76060?
high, CVSS 8.8
Is CVE-2026-76060 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-76060 be mitigated?
Upgrade ZoneMinder to version 1.38.3 or later immediately. Download the installer from https://zoneminder.com/downloads or obtain the source code from https://github.com/ZoneMinder/zoneminder. Apply the fix from security advisory GHSA-88m4-hrgp-m9v3. Restrict user permissions to limit the number of authenticated users with View Events access. Monitor for suspicious activity in web server logs.
CVSS
8.8
Vendor
ZoneMinder
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
ZoneMinder 1.37.48, ZoneMinder 1.38.3
Mitigation
Upgrade ZoneMinder to version 1.38.3 or later immediately. Download the installer from https://zoneminder.com/downloads or obtain the source code from https://github.com/ZoneMinder/zoneminder. Apply the fix from security advisory GHSA-88m4-hrgp-m9v3. Restrict user permissions to limit the number of authenticated users with View Events access. Monitor for suspicious activity in web server logs.
ZoneMinder versions 1.37.48 and 1.38.3 contain an authenticated OS command injection vulnerability (CVE-2026-76060) in the event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server. CISA reports a public proof-of-concept has been released, but no confirmed active exploitation has been observed in the wild. The vendor has released version 1.38.3 as a fix.