CVE-2026-76060 is an authenticated OS command-injection vulnerability in ZoneMinder's event export functionality. The exportFile HTTP request parameter is incorporated without sanitization into a shell command executed through PHP's exec() function. An authenticated user granted the View Events permission can supply crafted input to execute arbitrary operating-system commands in the security context of the ZoneMinder service.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This four-file repository is a functional Python proof of concept for OS command injection in ZoneMinder event export handling, documented as affecting ZoneMinder versions 1.37.48 through 1.38.1 (with 1.36.x stated to be unaffected). The vulnerability is in `web/includes/download_functions.php`, where a monitor name is inserted into shell commands for ffmpeg and tar/zip export processing using unsafe manual single-quote wrapping rather than `escapeshellarg()`. `poc.py` authenticates as `medpriv`, creates a monitor whose name closes the quote and injects `touch /tmp/pwned`, creates an event, then authenticates as `lowpriv` and requests a ZIP event export. The export reaches the shell-command sinks and executes the injected command. The script deletes its created monitor/event and runs `docker exec` to confirm the marker file exists. `compose.yml` provisions a reproducible ZoneMinder 1.38.1 plus MariaDB lab at host port 8082, while `init.sql` enables authentication and creates admin, monitor-creation, and event-export user roles. The exploit demonstrates a stored, authenticated cross-privilege command-execution chain: one account plants the malicious monitor name and another account triggers its execution through export.
This four-file repository is an operational Python proof of concept for a stored OS command injection in ZoneMinder event export functionality, reportedly affecting ZoneMinder 1.37.48 through 1.38.1; the 1.36.x branch is stated to be unaffected. `poc.py` authenticates as a medium-privileged user, creates a monitor whose name contains shell-quote breakout syntax and `touch /tmp/pwned`, creates an event, then authenticates as a lower-privileged user and triggers a ZIP event export. The vulnerable ZoneMinder export logic incorporates the monitor name into ffmpeg and tar/zip shell command strings using manual single-quote wrapping rather than safe shell escaping, allowing the stored name to execute commands when export occurs. The PoC cleans up its API-created monitor/event and confirms execution with `docker exec` against the local container. `compose.yml` provisions MariaDB and a privileged ZoneMinder 1.38.1 container exposed as localhost:8082, while `init.sql` enables authentication and creates admin, monitor-creation-capable, and export-capable test accounts. `README.md` explains the two-role attack chain, vulnerable command sinks, affected versions, and mitigation using `escapeshellarg()`.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unpatched vulnerability identified as CVE-2026-76060, assessed as network-accessible with low attack complexity and requiring low privileges. The provided CVSS v3.0 vector indicates high confidentiality, integrity, and availability impact.
An authenticated operating-system command injection vulnerability in ZoneMinder event export functionality. A user possessing the View Events permission can inject commands through the exportFile HTTP parameter, which is unsafely passed to PHP exec(), resulting in arbitrary command execution on the server.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.