Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Remote Code Execution via HTTP API in ZLMediaKit | |
| Weaknesses | CWE-284 CWE-94 |
Mon, 21 Sep 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zlmediakit
Zlmediakit zlmediakit |
|
| Vendors & Products |
Zlmediakit
Zlmediakit zlmediakit |
Mon, 21 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to the setServerConfig API endpoint, which permits overwriting the ffmpeg.snap configuration parameter with arbitrary shell commands. These commands are subsequently executed through the getSnap API endpoint with the privileges of the ZLMediaKit process. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-21T20:59:18.759Z
Reserved: 2026-07-30T00:00:00.000Z
Link: CVE-2026-67827
No data.
Status : Received
Published: 2026-09-21T21:17:08.827
Modified: 2026-09-21T21:17:08.827
Link: CVE-2026-67827
No data.
OpenCVE Enrichment
Updated: 2026-09-21T23:30:18Z