CVE-2026-28286 describes a critical vulnerability in ZimaOS version 1.5.2-beta3, affecting Zima devices and x86-64 systems with UEFI. The vulnerability allows authenticated users to bypass frontend restrictions and create files or directories in sensitive operating system paths (e.g., /etc, /usr) by directly interacting with the API. This is due to improper validation of target paths, granting unauthorized write access to critical system directories. Rated 9.9 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H), this flaw can be exploited remotely with low attack complexity and requires only low privileges, leading to complete compromise of confidentiality, integrity, and availability. Currently, there is no known public patch, and it is not listed in CISA's KEV catalog. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available, the vulnerability has garnered some community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.2CPE matchmatch criteria | cpe:2.3:o:zimaspace:zimaos:1.5.2:beta3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.