Known CVE
ZimaOS - Authentication Bypass
ZimaOS <= 1.5.0 contains a broken authentication caused by improper password validation for known system service accounts in the login function, letting attackers authenticate with any password for these accounts, exploit requires knowledge of common usernames.
CVE-2026-21891
Critical2026CVSS 9.4CWE-287
cve2026 · zimaos · auth-bypass · broken-auth · vkev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website