CVE-2026-28286General(zimaspace / zimaos)

MEDIUMCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch zimaspace zimaos systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, the application enforces restrictions in the frontend/UI to prevent users from creating files or folders in internal OS paths. However, when interacting directly with the API, the restrictions are bypass-able. By sending a crafted request targeting paths like /etc, /usr, or other sensitive system directories, the API successfully creates files or directories in locations where normal users should have no write access. This indicates that the API does not properly validate the target path, allowing unauthorized operations on critical system directories. No known patch is publicly available.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zimaos

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • General: 4 classified signals
  • Disclosure: 3 classified signals
  • Peaked 4d ago at 4 mentions (2026-03-02); latest day: 1
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
zimaos

1 version affected across 1 product

Deep dive

Activity timeline9 mentions / 5d
01234Mentions · 2026-03-02: 4Mentions · 2026-03-03: 2Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-04-07: 1PoC Mentioned / Linked · 2026-04-07: 1Exploit Tool / Code · 2026-04-07: 1Patch / Workaround · 2026-03-03: 1Technical Details · 2026-03-02: 1Technical Details · 2026-03-03: 2Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-04-07: 103-0203-0303-0503-0604-07
Signal classification4 categories
General
444.4%
Disclosure
333.3%
Patch
111.1%
PoC
111.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-024
Disclosure2General2
2026-03-032
Disclosure1Patch1
2026-03-051
General1
2026-03-061
General1
2026-04-071
PoC1
Full discourse9 posts
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ CVE-2026-28286: ZimaOS Privilege Escalation Vulnerability PoC: https://github.com/Rushi9/zimaos-cve-2026-28286-arbitrary-file-write?tab=readme-ov-file A privilege escalation vulnerability discovered in Zimaspace's ZimaOS. It enables attackers to circumvent API-level restrictions and gain unauthorized write access to sensitive system directories.

    Post summary

    CVE-2026-28286 is a privilege escalation flaw in ZimaOS; a PoC is publicly available on GitHub demonstrating arbitrary file write to protected directories.

    0702395.8K
    218.4K followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-28286 (CVSS:8.5, HIGH) is Analyzed. ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, t..https://nvd.nist.gov/vuln/detail/CVE-2026-28286 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces a CVE with its CVSS score and a product reference, but does not provide a PoC, exploit, patch, or active exploitation evidence.

    0000029
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-28286 (CVSS:8.5, HIGH) is Undergoing Analysis. ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, t..https://nvd.nist.gov/vuln/detail/CVE-2026-28286 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post notes CVE‑2026‑28286 with a CVSS of 8.5 and high severity, but provides no exploits, PoCs, or mitigation details.

    0000034
    173 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A `ZimaOS` vulnerability (CVE-2026-28286) allows unauthorized file/folder creation in restricted system directories via API. Update `ZimaOS` for #security. #ZimaOS #infosec https://www.pulsepatch.io/posts/cve-2026-28286-zimaos-unauthorized-file-creation

    Post summary

    The post announces CVE-2026-28286, describing unauthorized file creation via API and urges users to update ZimaOS to mitigate the issue.

    0000037
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28286 Path Traversal in ZimaOS 1.5.2-beta3 Enabling Unauthorized File System M... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28286 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A path traversal vulnerability (CVE-2026-28286) in ZimaOS 1.5.2-beta3 is disclosed, allowing unauthorized file system access.

    0000061
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-28286 ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, the application enforces restrictions in the fr… https://www.cve.org/CVERecord?id=CVE-2026-28286 ----- Traducción: CVE-2026-28286 Zim… http://infoflow.cloud`

    Post summary

    The post references CVE-2026-28286 and links to its CVE record but provides no further technical, exploit, or mitigation details.

    0000036
    55 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-28286: HIGH] ZimaOS, a fork of CasaOS, faces a security flaw in version 1.5.2-beta3 where API restrictions can be bypassed, allowing unauthorized access to critical system directories.#cve,CVE-2026-28286,#cybersecurity https://cvefind.com/CVE-2026-28286

    Post summary

    A high‑severity vulnerability (CVE‑2026‑28286) in ZimaOS 1.5.2‑beta3 allows bypassing API restrictions to access critical system directories.

    0000070
    590 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-28286 ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, the application enforces restrictions in the fr… https://www.cve.org/CVERecord?id=CVE-2026-28286

    Post summary

    The text references CVE-2026-28286, noting a version and a restriction enforcement, but offers no further technical, exploit, or mitigation details.

    00000359
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-28286 - High ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, the application enforces restrictions in the frontend/UI to prevent user... https://www.thehackerwire.com/vulnerability/CVE-2026-28286/ https://t.co/TmXJAdbgWt

    Post summary

    A new high‑severity vulnerability (CVE‑2026‑28286) in ZimaOS version 1.5.2‑beta3 is reported, with limited details provided in the brief announcement.

    0000047
    122 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSzimaspacezimaos1.5.2--

Explore more