Critical Flaw in ZoneMinder Video Surveillance Software Could Allow Full Server Takeover
Security researchers have identified a serious vulnerability in ZoneMinder, an open-source video surveillance system used by businesses worldwide to manage security cameras. The flaw, tracked as CVE-2026-76060, is an OS command injection issue affecting ZoneMinder versions 1.37.48 and 1.38.3. It has been rated 8.8 out of 10 on the CVSS severity scale, indicating a high risk.
If exploited, an attacker who already has an authenticated account on the system could inject and run unauthorized commands on the server, potentially gaining full remote code execution as the web server user. This means an attacker could take control of the machine running the surveillance software, access sensitive data, or use it as a foothold to move further into a business's network.
While exploitation requires an existing authenticated account, businesses using ZoneMinder for physical security monitoring should treat this as a priority issue, especially if account credentials are shared, weak, or exposed. Vendors and security teams typically issue patches soon after such disclosures, so checking for updates is essential.