Description
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions up to and including 1.5.0, the application checks the validity of the username but appears to skip, misinterpret, or incorrectly validate the password when the provided username matches a known system service account. The application's login function fails to properly handle the password validation result for these users, effectively granting authenticated access to anyone who knows one of these common usernames and provides any password. As of time of publication, no known patched versions are available.
Published: 2026-01-08
Score: 9.4 Critical
EPSS: 6.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in ZimaOS versions up to 1.5.0 allows an attacker to bypass authentication when the username matches a known system service account. During login, the system disregards or misinterprets the password validation step for these users, permitting access with any password. As a consequence, anyone who knows one of the common system usernames can gain full administrative privileges, which threatens confidentiality, integrity, and availability of the device. Based on the description, it is inferred that this flaw can be exploited simply by submitting a login request with a valid system account name and an arbitrary password, without the need for additional privileges or system exploitation. Affected systems include IceWhaleTech ZimaOS, an operating system for Zima devices and x86‑64 UEFI systems. All releases up to and including version 1.5.0 contain the flaw, and no patched version is currently available. The risk is significant: a CVSS score of 9.4 reflects critical impact and easy exploitation. The EPSS probability of 6 % indicates a non‑trivial likelihood of attacks. The vulnerability is not listed in the CISA KEV catalog, but the high severity and the presence of remote login interfaces make it a prime target for adversaries. The most likely attack vector is the exposed login service; if this interface is reachable over a network, attackers can acquire full control of the device without additional privileges.

Affected Systems

IceWhaleTech ZimaOS on Zima devices and x86‑64 UEFI systems, all releases up to version 1.5.0

Risk and Exploitability

This flaw carries a CVSS score of 9.4 and an EPSS score of 6 %, indicating a high probability of exploitation, especially when the login interface is exposed remotely. Although not yet listed in the CISA KEV catalog, the ease of bypassing authentication makes it a compelling target for attackers seeking to gain full system control.

Generated by OpenCVE AI on June 6, 2026 at 15:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable or rename all system service accounts that can authenticate through the ZimaOS login interface.
  • Enable multi‑factor authentication or enforce strict password policies to ensure that incorrect credentials do not grant access.
  • Restrict the login service to trusted IP ranges and block unknown or remote access when possible.
  • Monitor the system for repeated login attempts using known system account names and investigate any suspicious activity.
  • Notify IceWhaleTech of the vulnerability and apply any future patches or updates as soon as they become available.

Generated by OpenCVE AI on June 6, 2026 at 15:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 12 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Zimaspace
Zimaspace zimaos
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:zimaspace:zimaos:*:*:*:*:*:*:*:*
Vendors & Products Zimaspace
Zimaspace zimaos

Mon, 12 Jan 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Icewhaletech
Icewhaletech zimaos
Vendors & Products Icewhaletech
Icewhaletech zimaos

Thu, 08 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
Description ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions up to and including 1.5.0, the application checks the validity of the username but appears to skip, misinterpret, or incorrectly validate the password when the provided username matches a known system service account. The application's login function fails to properly handle the password validation result for these users, effectively granting authenticated access to anyone who knows one of these common usernames and provides any password. As of time of publication, no known patched versions are available.
Title ZimaOS has Authentication Bypass via System-Level Username
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Icewhaletech Zimaos
Zimaspace Zimaos
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-01-08T15:55:23.245Z

Reserved: 2026-01-05T17:24:36.929Z

Link: CVE-2026-21891

cve-icon Vulnrichment

Updated: 2026-01-08T14:52:30.079Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-08T14:15:57.403

Modified: 2026-01-12T17:13:00.240

Link: CVE-2026-21891

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-06T15:15:23Z

Weaknesses