Vulnerability record · CVE-2023-26035 · published 25 February 2023
CVE-2023-26035: ZoneMinder snapshot action missing authorization leads to RCE
Zoneminder · Zoneminder
ZoneMinder versions before 1.36.33 and 1.37.33 lack a permissions check on the snapshot action, which accepts an id meant to fetch an existing monitor but can instead be given an object that creates a new one. The supplied id is later passed to shell_exec via TriggerOn, allowing unauthenticated remote code execution. It matters because internet-facing camera management servers can be fully compromised without credentials.
Description
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are vulnerable to Unauthenticated Remote Code Execution via Missing Authorization. There are no permissions check on the snapshot action, which expects an id to fetch an existing monitor but can be passed an object to create a new one instead. TriggerOn ends up calling shell_exec using the supplied Id. This issue is fixed in This issue is fixed in versions 1.36.33 and 1.37.33.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with a CVSS of 9.8 and very high EPSS, though not in KEV.
What it is
ZoneMinder versions before 1.36.33 and 1.37.33 lack a permissions check on the snapshot action, which accepts an id meant to fetch an existing monitor but can instead be given an object that creates a new one. The supplied id is later passed to shell_exec via TriggerOn, allowing unauthenticated remote code execution. It matters because internet-facing camera management servers can be fully compromised without credentials.
Impact
An unauthenticated attacker can execute arbitrary shell commands on the ZoneMinder host, leading to full server compromise, data theft, and use of the host as a pivot into the camera network.
Attack surface
Reachable over the network through the snapshot action of the ZoneMinder web interface; the CVSS vector shows no privileges or user interaction required, and the description states the flaw is unauthenticated.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.80462, 99.6th percentile) and public exploit material exists via the Packet Storm command injection reference. No ransomware group usage is documented.
What to do
- Upgrade ZoneMinder to 1.36.33 or 1.37.33 (or later) as the vendor patch.
- If immediate patching is not possible, restrict access to the ZoneMinder web interface to trusted networks or place it behind an authenticated reverse proxy.
- Remove or disable the snapshot action until the upgrade is applied.
- Audit the ZoneMinder host for unexpected processes, cron entries, and outbound connections after exposure.
- Monitor vendor advisory GHSA-72rg-h4vf-29gr for any further guidance.
Detection
- Inspect web server logs for requests to the snapshot action with unexpected or object-shaped id parameters.
- Look for shell_exec child processes spawned by the ZoneMinder web/PHP process.
- Alert on outbound network connections or command-and-control traffic originating from the ZoneMinder host.
- Review ZoneMinder monitor creation events that were not initiated by an authenticated administrator.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-26035 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-26035), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.