CVE-2026-88260
Summary
| CVE | CVE-2026-88260 |
|---|---|
| State | PUBLISHED |
| Assigner | FSI |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-11 03:16:24 UTC |
| Updated | 2026-09-11 17:19:31 UTC |
| Description | Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OAM (Build 109). |
Risk And Classification
Primary CVSS: v4.0 8.7 HIGH from 09832df1-09c1-45b4-8a85-16c601d30feb
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.002000000 probability, percentile 0.098940000 (date 2026-09-13)
Problem Types: CWE-288 | CWE-1286 | CWE-288 CWE-288 Authentication bypass using an alternate path or channel | CWE-1286 CWE-1286 Improper validation of syntactic correctness of input
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 09832df1-09c1-45b4-8a85-16c601d30feb | Secondary | 8.7 | HIGH | CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 8.7 | HIGH | CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
CVSS v4.0 Breakdown
Attack Vector
AdjacentAttack Complexity
LowAttack Requirements
NonePrivileges Required
NoneUser Interaction
NoneConfidentiality
HighIntegrity
HighAvailability
HighSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Brainzcompany | Zenius EMS 8.0 | affected OAM (Build 109) custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.brainz.co.kr/Features | 09832df1-09c1-45b4-8a85-16c601d30feb | www.brainz.co.kr | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: darbong(이민희) (en)
There are currently no legacy QID mappings associated with this CVE.