CVE-2026-21891

CRITICAL EXPLOITED NUCLEI

ZimaOS <= 1.5.0 - Improper Authentication via Service Account Username

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2026-21891 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.

Description

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions up to and including 1.5.0, the application checks the validity of the username but appears to skip, misinterpret, or incorrectly validate the password when the provided username matches a known system service account. The application's login function fails to properly handle the password validation result for these users, effectively granting authenticated access to anyone who knows one of these common usernames and provides any password. As of time of publication, no known patched versions are available.

Nuclei Templates (1)

ZimaOS - Authentication Bypass
CRITICALVERIFIEDby DhiyaneshDk
Shodan: html:"ZimaOS"

References (1)

Core 1
Core References

Scores

CVSS v3 9.4
EPSS 0.0636
EPSS Percentile 91.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2026-03-07
CWE
CWE-287
Status published
Products (1)
zimaspace/zimaos < 1.5.0
Published Jan 08, 2026
Tracked Since Feb 18, 2026