Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to the setServerConfig API endpoint, which permits overwriting the ffmpeg.snap configuration parameter with arbitrary shell commands. These commands are subsequently executed through the getSnap API endpoint with the privileges of the ZLMediaKit process.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 21 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Remote Code Execution via HTTP API in ZLMediaKit | |
| Weaknesses | CWE-284 CWE-94 |
Mon, 21 Sep 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zlmediakit
Zlmediakit zlmediakit |
|
| Vendors & Products |
Zlmediakit
Zlmediakit zlmediakit |
Mon, 21 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to the setServerConfig API endpoint, which permits overwriting the ffmpeg.snap configuration parameter with arbitrary shell commands. These commands are subsequently executed through the getSnap API endpoint with the privileges of the ZLMediaKit process. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-21T20:59:18.759Z
Reserved: 2026-07-30T00:00:00.000Z
Link: CVE-2026-67827
No data.
Status : Received
Published: 2026-09-21T21:17:08.827
Modified: 2026-09-21T21:17:08.827
Link: CVE-2026-67827
No data.
OpenCVE Enrichment
Updated: 2026-09-21T23:30:18Z