PT-2026-23517 · Casaos+1 · Casaos+1

Rushi9

·

Published

2026-03-05

·

Updated

2026-03-12

·

CVE-2026-28442

CVSS v3.1

8.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZimaOS version 1.5.2-beta3
Description ZimaOS, a fork of CasaOS, exhibits a security issue where restrictions on deleting internal system files and folders can be bypassed through manipulation of the API. Specifically, altering the path parameter in a delete request allows users to remove sensitive operating system files and directories. The backend does not validate if the targeted path is within restricted system locations, indicating improper input validation and broken access control on filesystem operations. The API endpoint used for deletion accepts a path parameter that is not properly sanitized. The path parameter is vulnerable to manipulation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28442
GHSA-Q5HP-59WM-9XQ3

Affected Products

Casaos
Zimaos