← Back to search

CVE-2026-67827

9.8 CRITICALpublic exploit available

Published 2026-09-21 · Updated 2026-09-24

AI risk analysis

Summary
The flaw allows remote attackers to execute arbitrary shell commands via the setServerConfig API endpoint, leading to Remote Code Execution (RCE). This is critical because it can be exploited without authentication, providing full control over the system.
Exploitability
Exploitation is relatively easy due to the unauthenticated access required. Attackers need to send a request to the setServerConfig API with a malicious payload.
Blast radius
If exploited, this flaw could result in complete system compromise, allowing attackers to execute arbitrary commands and potentially gain full control over the server running ZLMediaKit.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the setServerConfig API endpoint or restrict access to it to authenticated users only. If a fixed version is available, upgrade to the latest version: 'Upgrade to the latest version of ZLMediaKit that includes the fix for CVE-2026-67827'.
rceauth-bypassapihttpremote

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to the setServerConfig API endpoint, which permits overwriting the ffmpeg.snap configuration parameter with arbitrary shell commands. These commands are subsequently executed through the getSnap API endpoint with the privileges of the ZLMediaKit process.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-94

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.