Unsafe reflection in ZoneMinder - #VU153356
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary operating-system commands as the filter process.
The vulnerability exists due to unsafe reflection in ZM_Object::set(), invoked by the filterdebug modal, when processing request-supplied filter keys before authorization. A remote user can send a specially crafted GET request with fid=0 and filter[save] followed by filter[execute] to execute arbitrary operating-system commands as the filter process.
Exploitation requires a working zmfilter.pl and a matching event with Executed=0. An enabled account with Events=None and System=None is sufficient.