Skip to content

Known CVE

ZimaOS - Authentication Bypass

ZimaOS <= 1.5.0 contains a broken authentication caused by improper password validation for known system service accounts in the login function, letting attackers authenticate with any password for these accounts, exploit requires knowledge of common usernames.

CVE-2026-21891

Critical2026CVSS 9.4CWE-287

cve2026 · zimaos · auth-bypass · broken-auth · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website