CVE-2026-67827
9.8ZLMediaKit · ZLMediaKit
An incorrect access control vulnerability in the ZLMediaKit HTTP API allows unauthenticated remote attackers to achieve remote code execution via the setServerConfig endpoint.
Executive summary
A critical remote code execution vulnerability in ZLMediaKit allows unauthenticated attackers to execute arbitrary system commands, posing a severe risk to system integrity and availability.
Vulnerability
This vulnerability involves improper access control within the HTTP API module, specifically in the setServerConfig API endpoint. An unauthenticated attacker can overwrite the ffmpeg.snap configuration parameter with arbitrary shell commands, which are subsequently executed with the privileges of the ZLMediaKit process when the getSnap API endpoint is invoked.
Business impact
The ability for an unauthenticated remote attacker to execute arbitrary code on the host system represents a total compromise of the application environment. Given the CVSS score of 9.8, this flaw could lead to complete system takeover, unauthorized data access, and potential lateral movement within the network. Such an incident would likely result in significant operational downtime and severe reputational damage.
Remediation
Immediate Action: Review the official ZLMediaKit security advisory linked in the references to identify patched versions or commit implementations and apply them immediately.
Proactive Monitoring: Monitor server access logs for unusual requests to the setServerConfig or getSnap API endpoints, particularly those originating from untrusted or external IP addresses.
Compensating Controls: Implement strict network access controls or a Web Application Firewall (WAF) to block unauthorized access to the ZLMediaKit HTTP API management endpoints.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability is classified as critical due to its potential for unauthenticated remote code execution. Security teams must prioritize identifying instances of ZLMediaKit within their infrastructure and restrict access to the affected API endpoints until a formal patch can be applied. Failure to address this flaw leaves the system exposed to full remote control by unauthorized actors.
History
CVE Brief tracked this CVE 3 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.8 (3.1) from cvelistV5
- Analyst report written
- Published in the daily brief critical section, early-warning entry