Use of Hard-coded Cryptographic Key in ZoneMinder - #VU153358
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication and gain administrator access.
The vulnerability exists due to use of a hard-coded, publicly known cryptographic key in ZoneMinder's JWT authentication when validating login tokens. A remote attacker can submit an HTTP request containing a forged administrator JWT signed with the published default key to bypass authentication and gain administrator access.
Exploitation requires authentication to be enabled and ZM_AUTH_HASH_SECRET to remain at its shipped default. Token verification using this secret is shared by the web UI, API, and nph-zms/zmu.