PT-2026-23517 · Casaos+1 · Casaos+1
Rushi9
·
Published
2026-03-05
·
Updated
2026-03-12
·
CVE-2026-28442
CVSS v3.1
8.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ZimaOS version 1.5.2-beta3
Description
ZimaOS, a fork of CasaOS, exhibits a security issue where restrictions on deleting internal system files and folders can be bypassed through manipulation of the API. Specifically, altering the path parameter in a delete request allows users to remove sensitive operating system files and directories. The backend does not validate if the targeted path is within restricted system locations, indicating improper input validation and broken access control on filesystem operations. The API endpoint used for deletion accepts a path parameter that is not properly sanitized. The
path parameter is vulnerable to manipulation.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Casaos
Zimaos