CVE-2023-26035 HIGH

CVE-2023-26035: ZoneMinder vulnerable to Missing Authorization

Vendor Zoneminder
Product zoneminder
Weakness CWE-862 · Missing authorization
Published February 25, 2023
Last update February 13, 2025

CVSS base score

7.2/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are vulnerable to Unauthenticated Remote Code Execution via Missing Authorization. There are no permissions check on the snapshot action, which expects an id to fetch an existing monitor but can be passed an object to create a new one instead. TriggerOn ends up calling shell_exec using the supplied Id. This issue is fixed in This issue is fixed in versions 1.36.33 and 1.37.33.

Key dates

02Disclosure timeline

February 25, 2023 CVE published
February 13, 2025 Record updated

Related vulnerabilities

04Related CVE