← Vulnerability feed

Vulnerability record · CVE-2023-26035 · published 25 February 2023

CVE-2023-26035: ZoneMinder snapshot action missing authorization leads to RCE

Zoneminder · Zoneminder

ZoneMinder versions before 1.36.33 and 1.37.33 lack a permissions check on the snapshot action, which accepts an id meant to fetch an existing monitor but can instead be given an object that creates a new one. The supplied id is later passed to shell_exec via TriggerOn, allowing unauthenticated remote code execution. It matters because internet-facing camera management servers can be fully compromised without credentials.

9.8 CVSS 3.1 Critical EPSS 80% · top 0.4% CWE-862 · Missing authorization
9.8CVSS 3.1 base score
80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are vulnerable to Unauthenticated Remote Code Execution via Missing Authorization. There are no permissions check on the snapshot action, which expects an id to fetch an existing monitor but can be passed an object to create a new one instead. TriggerOn ends up calling shell_exec using the supplied Id. This issue is fixed in This issue is fixed in versions 1.36.33 and 1.37.33.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution with a CVSS of 9.8 and very high EPSS, though not in KEV.

What it is

ZoneMinder versions before 1.36.33 and 1.37.33 lack a permissions check on the snapshot action, which accepts an id meant to fetch an existing monitor but can instead be given an object that creates a new one. The supplied id is later passed to shell_exec via TriggerOn, allowing unauthenticated remote code execution. It matters because internet-facing camera management servers can be fully compromised without credentials.

Impact

An unauthenticated attacker can execute arbitrary shell commands on the ZoneMinder host, leading to full server compromise, data theft, and use of the host as a pivot into the camera network.

Attack surface

Reachable over the network through the snapshot action of the ZoneMinder web interface; the CVSS vector shows no privileges or user interaction required, and the description states the flaw is unauthenticated.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.80462, 99.6th percentile) and public exploit material exists via the Packet Storm command injection reference. No ransomware group usage is documented.

What to do

  • Upgrade ZoneMinder to 1.36.33 or 1.37.33 (or later) as the vendor patch.
  • If immediate patching is not possible, restrict access to the ZoneMinder web interface to trusted networks or place it behind an authenticated reverse proxy.
  • Remove or disable the snapshot action until the upgrade is applied.
  • Audit the ZoneMinder host for unexpected processes, cron entries, and outbound connections after exposure.
  • Monitor vendor advisory GHSA-72rg-h4vf-29gr for any further guidance.

Detection

  • Inspect web server logs for requests to the snapshot action with unexpected or object-shaped id parameters.
  • Look for shell_exec child processes spawned by the ZoneMinder web/PHP process.
  • Alert on outbound network connections or command-and-control traffic originating from the ZoneMinder host.
  • Review ZoneMinder monitor creation events that were not initiated by an authenticated administrator.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-26035 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-3882Zoneminder code injection vulnerabilityUnspecified "Command Injection" vulnerability in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary commands via (1) the exec…EPSS 3.5%9.8CVE-2025-65791Zoneminder os command injection vulnerabilityZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() f…EPSS 1.7%9.8CVE-2024-43360Zoneminder sql injection vulnerabilityZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability.…EPSS 6.2%9.8CVE-2023-26036Zoneminder untrusted search path vulnerabilityZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior …EPSS 0.90%9.8CVE-2023-26037Zoneminder sql injection vulnerabilityZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior …EPSS 0.61%9.8CVE-2022-29806ZoneMinder path traversal in language setting enables remote code executionZoneMinder before 1.36.13 allows remote code execution through an invalid language value, with a path traversal weakness (CWE-22) that lets an attack…EPSS 67%analysed9.8CVE-2019-8423Zoneminder sql injection vulnerabilityZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.EPSS 1.6%9.8CVE-2019-8424Zoneminder sql injection vulnerabilityZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2023-26035), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.