CVE-2026-67827
Last modified
CVE-2026-67827 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to the setServerConfig API endpoint, which permits overwriting the ffmpeg.snap configuration parameter with arbitrary shell commands. These commands are subsequently executed through the getSnap API endpoint with the privileges of the ZLMediaKit process.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to the setServerConfig API endpoint, which permits overwriting the ffmpeg.snap configuration parameter with arbitrary shell commands. These commands are subsequently executed through the getSnap API endpoint with the privileges of the ZLMediaKit process.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | — | n/a |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-67827?
How severe is CVE-2026-67827?
How do I fix CVE-2026-67827?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6778Invalid pointer in the Audio/Video: Playback component. This…5.3
- CVE-2026-6779Other issue in the JavaScript Engine component. This vulnera…5.3
- CVE-2026-6780Denial-of-service in the Audio/Video: Playback component. Th…7.5
- CVE-2026-6781Denial-of-service in the Audio/Video: Playback component. Th…7.5
- CVE-2026-6782Information disclosure in the IP Protection component. This …7.5
- CVE-2026-67822Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overfl…9.8
- CVE-2026-6783Incorrect boundary conditions, integer overflow in the Audio…5.3
- CVE-2026-6784Memory safety bugs present in Firefox 149 and Thunderbird 14…7.5
- CVE-2026-67846Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41…7.8
- CVE-2026-6785Memory safety bugs present in Firefox ESR 115.34, Firefox ES…7.5
- CVE-2026-67854SQL Injection vulnerability in Qcms v.6.0.6 allows a remote …9.8
- CVE-2026-67855open62541 contains a heap use-after-free in the GDS PushMana…7.5
Are you affected by CVE-2026-67827?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
