SB2026100655 - Multiple vulnerabilities in ZoneMinder
Published: October 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 9 vulnerabilities.
1) Unsafe reflection (CVE-ID: N/A)
CWE-ID: CWE-470 - Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary operating-system commands as the filter process.
The vulnerability exists due to unsafe reflection in ZM_Object::set(), invoked by the filterdebug modal, when processing request-supplied filter keys before authorization. A remote user can send a specially crafted GET request with fid=0 and filter[save] followed by filter[execute] to execute arbitrary operating-system commands as the filter process.
Exploitation requires a working zmfilter.pl and a matching event with Executed=0. An enabled account with Events=None and System=None is sufficient.
2) Heap-based buffer overflow (CVE-ID: N/A)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to corrupt heap memory.
The vulnerability exists due to a heap-based buffer overflow in Image::ReadJpeg() when decoding a JPEG with dimensions larger than the configured monitor image. A local user can replace the monitored file with a specially crafted JPEG to corrupt heap memory.
Exploitation requires a File source-type monitor, which is not the default configuration, and write access to its source file. No ZoneMinder authentication is required.
3) Use of Hard-coded Cryptographic Key (CVE-ID: N/A)
CWE-ID: CWE-321 - Use of Hard-coded Cryptographic Key
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authentication and gain administrator access.
The vulnerability exists due to use of a hard-coded, publicly known cryptographic key in ZoneMinder's JWT authentication when validating login tokens. A remote attacker can submit an HTTP request containing a forged administrator JWT signed with the published default key to bypass authentication and gain administrator access.
Exploitation requires authentication to be enabled and ZM_AUTH_HASH_SECRET to remain at its shipped default. Token verification using this secret is shared by the web UI, API, and nph-zms/zmu.
4) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive event data.
The vulnerability exists due to incorrect authorization in the AJAX dispatcher in web/index.php and the raw branch of web/ajax/stats.php when handling AJAX requests with view=none. A remote attacker can send a request containing view=none, request=stats, raw=1, and a matching event/frame ID pair to disclose sensitive event data.
Exploitation requires ZM_OPT_USE_AUTH=1, ZM_RECORD_EVENT_STATS=1, and a corresponding Stats row. Event and frame IDs are sequential integers.
5) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to create unauthorized Frame and EventData database records for events belonging to explicitly denied monitors.
nThe vulnerability exists due to incorrect authorization in the FramesController::add() and EventDataController::add() handlers when processing API record-creation requests. A remote user can submit POST requests to /api/frames/add.json and /api/event_data/add.json using an Events=View account to create unauthorized Frame and EventData database records for events belonging to explicitly denied monitors.
nExploitation requires the API to be enabled and the account to have APIEnabled=1.
6) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to rename a zone belonging to an explicitly denied camera.
The vulnerability exists due to incorrect authorization in the ZonesController::edit() API route when processing zone edit requests without checking access to the zone's owning monitor. A remote user can send a zone rename request targeting a zone on a denied monitor to rename a zone belonging to an explicitly denied camera.
Exploitation requires authentication and API access to be enabled, an enabled account with APIEnabled=1 and global Monitors=Edit permission, and an existing zone on the denied monitor. The edit operation does not restart the monitor.
7) Authorization bypass through user-controlled key (CVE-ID: N/A)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose recorded JPEG frames from monitors they are denied access to.
The vulnerability exists due to authorization bypass through a user-controlled monitor ID in the native nph-zms CGI when serving recorded event media without checking access to the event's actual monitor. A remote user can supply an allowed monitor ID with an event ID belonging to a denied monitor, or omit the monitor parameter, to disclose recorded JPEG frames from monitors they are denied access to.
Exploitation requires knowledge of an event ID. The demonstrated viewer had Stream=View and Events=View permissions.
8) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary JavaScript in a viewer's browser.
The vulnerability exists due to improper neutralization of stored input in web/skins/classic/views/js/montage.js.php when rendering a monitor's DefaultPlayer value in the montage view. A remote user can submit a specially crafted Monitor.DefaultPlayer value through POST /api/monitors/edit/{id}.json to execute arbitrary JavaScript in a viewer's browser.
Exploitation requires monitor editing permission and a separate viewer opening the montage view. The monitor must be visible to that viewer and have Capturing set to a value other than None. The injected code executes within the page's existing nonce-bearing script.
9) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary JavaScript in the application origin.
The vulnerability exists due to improper neutralization of the nested filter identifier in web/skins/classic/views/filter.php and web/skins/classic/views/js/filter.js.php when rendering a filter page. A remote user can supply a crafted filter URL containing a top-level Id=1, a malicious filter[Id] value, and filter[Query] parameters to execute arbitrary JavaScript in the application origin.
Execution requires an authenticated user with Events View or Edit permission to open the crafted URL. The injected JavaScript runs inside a nonce-authorized script. Cross-site delivery under SameSite Strict was not tested.
Remediation
Install update from vendor's website.
References
- https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-vvx7-ghpv-jq98
- https://github.com/ZoneMinder/zoneminder/releases/tag/1.38.5
- https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-rpp4-xmqm-84ff
- https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-wmcc-x64g-jr84
- https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-vvw3-j4p4-4rgx
- https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-993c-fc6p-hpxg
- https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-f8h6-62c9-x6qr
- https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-4r2m-68p2-phf7
- https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-r44j-mvj8-cg9w
- https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-wqmm-rmvc-pc7r