CVE-2026-27470General(zoneminder / zoneminder)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

ZoneMinder is a free, open source closed-circuit television software application. In versions 1.36.37 and below and 1.37.61 through 1.38.0, there is a second-order SQL Injection vulnerability in the web/ajax/status.php file within the getNearEvents() function. Event field values (specifically Name and Cause) are stored safely via parameterized queries but are later retrieved and concatenated directly into SQL WHERE clauses without escaping. An authenticated user with Events edit and view permissions can exploit this to execute arbitrary SQL queries.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zoneminder

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-06); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
zoneminder

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-06: 1Mentions · 2026-03-10: 1Mentions · 2026-03-23: 1Technical Details · 2026-03-06: 103-0603-1003-23
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-061
Disclosure1
2026-03-101
General1
2026-03-231
General1
Full discourse3 posts
  • Albert @YZ9YT@yz9yt
    Disclosure

    CVE 8.8 ZoneMinder a webcam sistem SQLinjection discovered by me. https://www.cve.org/CVERecord?id=CVE-2026-27470

    Post summary

    A new CVE-2026-27470, identifying an SQL injection in ZoneMinder, was discovered and publicly referenced with minimal additional details.

    01021235
    1.3K followersView on X
  • Albert @YZ9YT@yz9yt
    General

    @rez0__ I should to do a video of my 3 CVEs with a Bugtraceai framework for 2 dollars run. Wallos High: https://www.cve.org/CVERecord?id=CVE-2026-27479 ZoneMinder High: https://www.cve.org/CVERecord?id=CVE-2026-27470 Piwigo Medium: https://www.cve.org/CVERecord?id=CVE-2026-27834

    Post summary

    The user plans to create a video on three CVEs, citing only their identifiers and a framework name, without providing technical details, PoC, exploits, or patch information.

    00001657
    1.3K followersView on X
  • Albert @YZ9YT@yz9yt
    General

    @carlosazaustre Y donde han puesto los CVEs que encontraron? yo te paso los que encontré con BugTraceAI Wallos - High https://www.cve.org/CVERecord?id=CVE-2026-27479 ZoneMinder - High https://www.cve.org/CVERecord?id=CVE-2026-27470 Piwigo (Pendiente de Disclosure) - High CVE-2026-27834

    Post summary

    The user lists several CVE IDs identified by BugTraceAI and links to their CVE.org pages, noting each as 'High' severity without providing further technical detail or evidence of exploitation.

    00010180
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appzoneminderzoneminder---

Explore more