External risk intelligence

ZLMediaKit HTTP API Improper Access Control Leading to Remote Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-67827

ZLMediaKit is a streaming media server framework often deployed as an edge service or public-facing API endpoint to handle media traffic. The vulnerability exists within its HTTP API module, which is commonly exposed to manage configuration and streaming operations, making it a likely candidate for internet-facing deployment.

Code Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the HTTP API of ZLMediaKit could allow unauthenticated attackers to execute arbitrary commands on affected systems. This is a critical issue because it could lead to a complete compromise of the server, impacting any services relying on ZLMediaKit for media streaming or management. The main concern is confirming relevance and exposure.

  • Unauthenticated attackers can run commands.
  • Critical flaw impacts server operations.
  • Confirm exposure to ZLMediaKit.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending unauthenticated requests to the HTTP API. This allows them to overwrite a configuration setting with malicious commands. When another API endpoint is later used, these commands are executed with the privileges of the running application, potentially leading to full system compromise.

  • Unauthenticated network access required.
  • Overwriting configuration via API endpoint.
  • Remote code execution with process privileges.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker to execute arbitrary shell commands on the server running ZLMediaKit. This could occur when an attacker sends a specially crafted request to the `setServerConfig` API endpoint, enabling them to overwrite configuration settings. When supported by the advisory, these commands could then be executed by the `getSnap` API, potentially impacting the confidentiality, integrity, and availability of the ZLMediaKit process and the underlying system.

  • Server configuration and process execution.
  • Unauthenticated API access overwrites settings.
  • Server compromise and data exposure.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in ZLMediaKit's HTTP API module, allowing unauthenticated remote code execution by overwriting configuration, requires immediate attention from teams managing streaming media infrastructure. The first practical move is to identify all instances of ZLMediaKit, determine their internet reachability and business criticality, and then assign ownership for remediation planning.

  • Identify ZLMediaKit instances and scope.
  • Verify internet exposure and criticality.
  • Plan remediation or risk reduction.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is ZLMediaKit?

ZLMediaKit is an open-source framework used to build high-performance streaming media servers. It handles tasks like video transmission, recording, and format conversion. Developers often use it to power live streaming services, where it functions as a backend engine for processing and distributing media traffic.

What does CWE-94 mean in the context of CVE-2026-67827?

CWE-94 refers to improper control of generation of code, often called Code Injection. In this vulnerability, it means the application inadvertently allows a user to input data that the system later treats as executable commands. Because the software fails to validate input, it blindly accepts and runs malicious shell instructions.

How does an attacker trigger this vulnerability?

An attacker exploits this by sending an unauthenticated request to the setServerConfig API endpoint to overwrite a configuration parameter. Crucially, the vulnerability is not triggered simply by reaching the server; it requires the specific action of injecting shell commands into that configuration. The malicious code then executes only when the getSnap API is invoked.

Why is this CVE considered relevant for my network?

According to Halo Surface Signal, ZLMediaKit is frequently deployed as an edge service or public-facing API to manage media streams. If your instance is accessible from the internet, it is at higher risk because the API module required for the attack is often exposed to the network to facilitate remote configuration and streaming control.

What should I do if I run ZLMediaKit?

Your priority is to establish a comprehensive inventory of all ZLMediaKit deployments within your environment. Once identified, evaluate whether each instance is exposed to the internet or reachable by untrusted networks. After assessing the business criticality of these systems, move quickly to assign internal ownership to plan and implement remediation.

References