AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-26039

HIGH · CVSS 7.1 EPSS 1.25% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-02-25 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2023-26039
Severity
HIGH
CVSS
7.1
EPSS
1.25%
Linux

Original NVD Description

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain an OS Command Injection via daemonControl() in (/web/api/app/Controller/HostController.php). Any authenticated user can construct an api command to execute any shell command as the web user. This issue is patched in versions 1.36.33 and 1.37.33.