TROYANOSYVIRUS
Back to CVEs

CVE-2026-28286

HIGH
8.5

Description

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, the application enforces restrictions in the frontend/UI to prevent users from creating files or folders in internal OS paths. However, when interacting directly with the API, the restrictions are bypass-able. By sending a crafted request targeting paths like /etc, /usr, or other sensitive system directories, the API successfully creates files or directories in locations where normal users should have no write access. This indicates that the API does not properly validate the target path, allowing unauthorized operations on critical system directories. No known patch is publicly available.

CVE Details

CVSS v3.1 Score8.5
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityHIGH
Privileges RequiredLOW
User InteractionNONE
Published3/2/2026
Last Modified3/5/2026
Sourcenvd
Honeypot Sightings0

Affected Products

zimaspace:zimaos

Weaknesses (CWE)

CWE-73

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.