CVE-2026-88260
—Auth Bypass and Remote Code Inclusion in Brainzcompany Zenius EMS 8.0
Brainzcompany Zenius EMS 8.0 contains two flaws that combine to enable remote code inclusion: an authentication bypass using an alternate path or channel (CWE-288) and improper validation of the syntactic correctness of input (CWE-1286). Per the CVSS 4.0 vector (adjacent attack vector, no privileges or user interaction required), an attacker with access to a network adjacent to the EMS server can reach the application, bypass authentication via the alternate path, and submit malformed input that the application accepts, causing it to include and execute attacker-controlled remote code. Successful exploitation carries high impact to confidentiality, integrity, and availability on the EMS host, with an overall CVSS 4.0 score of 8.7 (High). All Zenius EMS 8.0 deployments up to and including OAM (Build 109) are affected, so any organization running that release should treat itself as potentially exposed. There is currently no public proof-of-concept, no CISA KEV listing, and no confirmed exploitation in the wild.
What to do: Upgrade Zenius EMS 8.0 to the first build after OAM (Build 109) once Brainzcompany publishes a fixed release, and verify your currently deployed build. Until patching, restrict network access to the EMS server to trusted management segments, since exploitation requires adjacent-network access but no credentials or user interaction. No public PoC or KEV listing exists yet, so prioritize the upgrade on exposed management networks and monitor for vendor advisories or future KEV inclusion.
| Brainzcompany Zenius EMS | 8.0 through OAM (Build 109) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OAM (Build 109).
- Weakness
- CWE-288, CWE-1286
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.