{"id":"CVE-2026-67827","published":"2026-09-21T21:17:08.827","lastModified":"2026-09-24T13:17:10.397","description":"Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to the setServerConfig API endpoint, which permits overwriting the ffmpeg.snap configuration parameter with arbitrary shell commands. These commands are subsequently executed through the getSnap API endpoint with the privileges of the ZLMediaKit process.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-94"],"vendors":[],"products":[],"references":[{"url":"https://github.com/ZLMediaKit/ZLMediaKit/security/advisories/GHSA-qh3r-f727-ww9m","tags":[]},{"url":"https://github.com/ZLMediaKit/ZLMediaKit/security/advisories/GHSA-qh3r-f727-ww9m","tags":[]}],"exploitRefs":[{"url":"https://github.com/ZLMediaKit/ZLMediaKit/security/advisories/GHSA-qh3r-f727-ww9m","tags":[]},{"url":"https://github.com/ZLMediaKit/ZLMediaKit/security/advisories/GHSA-qh3r-f727-ww9m","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows remote attackers to execute arbitrary shell commands via the setServerConfig API endpoint, leading to Remote Code Execution (RCE). This is critical because it can be exploited without authentication, providing full control over the system.","exploitability":"Exploitation is relatively easy due to the unauthenticated access required. Attackers need to send a request to the setServerConfig API with a malicious payload.","blast_radius":"If exploited, this flaw could result in complete system compromise, allowing attackers to execute arbitrary commands and potentially gain full control over the server running ZLMediaKit.","remediation":"Disable the setServerConfig API endpoint or restrict access to it to authenticated users only. If a fixed version is available, upgrade to the latest version: 'Upgrade to the latest version of ZLMediaKit that includes the fix for CVE-2026-67827'.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","auth-bypass","api","http","remote"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:59:43.098Z"}}