CRITICAL

CVE-2023-26035

CVSS v3

9.8

CRITICAL

EPSS Score

49.6%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are vulnerable to Unauthenticated Remote Code Execution via Missing Authorization. There are no permissions check on the snapshot action, which expects an id to fetch an existing monitor but can be passed an object to create a new one instead. TriggerOn ends up calling shell_exec using the supplied Id. This issue is fixed in This issue is fixed in versions 1.36.33 and 1.37.33.

Technical details

Published
2/25/2023

Frequently asked questions

What is CVE-2023-26035?

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are vulnerable to Unauthenticated Remote Code Execution via Missing Authorization. There are no permissions check on the snapshot action, which expects an id to fetch an existing monitor but can be passed an object to create a new one instead. TriggerOn ends up calling shell_exec using the supplied Id. This issue is fixed in This issue is fixed in versions 1.36.33 and 1.37.33.

Is CVE-2023-26035 actively exploited?

Active exploitation of CVE-2023-26035 has not been confirmed. The EPSS score is 49.6%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-26035?

CVE-2023-26035 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2023-26035 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.