CVE-2026-88260 PUBLISHED

Assigner: FSI
Reserved: 10.09.2026 Published: 11.09.2026 Updated: 11.09.2026

Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion.

This issue affects Zenius EMS 8.0: through OAM (Build 109).

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Brainzcompany
Product Zenius EMS 8.0
Versions Default: unaffected
  • affected from 0 to OAM (Build 109) (incl.)

Credits

  • darbong(이민희) finder

References

Problem Types

  • CWE-288 Authentication bypass using an alternate path or channel CWE
  • CWE-1286 Improper validation of syntactic correctness of input CWE

Impacts

  • CAPEC-253 Remote Code Inclusion