Description
Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion.

This issue affects Zenius EMS 8.0: through OAM (Build 109).
Published: 2026-09-11
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Soon
AI Analysis

Impact

The vulnerability in Brainzcompany Zenius EMS 8.0 arises from an authentication bypass that can be achieved via an alternate path or channel, combined with improper validation of syntactic correctness of input. This flaw enables an attacker to inject code that the server will execute, resulting in remote code inclusion. The primary impact is remote code execution, allowing an attacker to compromise confidentiality, integrity, and availability of the affected system. The weakness is classified under CWE‑1286 Authentication Bypass and CWE‑288 Improper Validation.

Affected Systems

Brainzcompany Zenius EMS 8.0, Build OAM 109 is the only affected version identified. No additional affected products or versions are listed.

Risk and Exploitability

With a CVSS score of 8.7 the vulnerability is considered high severity. The EPSS score is not available, but the lack of an existing KEV listing does not diminish the risk posed by the flaw. The likely attack vector is remote, through the application’s web interface or other exposed channels that permit the use of the alternate authentication path. The vulnerability requires remote access to the application but does not demand local privileges or pre‑existing authentication, making it potentially exploitable by unauthenticated or low‑privilege attackers.

Generated by OpenCVE AI on September 11, 2026 at 04:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Acquire and install the latest official Zenius EMS version from Brainzcompany that addresses the authentication bypass and input validation issue.
  • Disable any unused alternate authentication paths or channels that may permit bypass, limiting access to the primary authentication mechanism.
  • Configure application and network security controls to reject requests that fail syntactic validation, and monitor logs for suspicious authentication activity to detect possible exploitation attempts.

Generated by OpenCVE AI on September 11, 2026 at 04:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Brainzcompany
Brainzcompany zenius Ems 8.0
Vendors & Products Brainzcompany
Brainzcompany zenius Ems 8.0

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OAM (Build 109).
Weaknesses CWE-1286
CWE-288
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Brainzcompany Zenius Ems 8.0
cve-icon MITRE

Status: PUBLISHED

Assigner: FSI

Published:

Updated: 2026-09-11T16:53:14.457Z

Reserved: 2026-09-10T00:46:49.862Z

Link: CVE-2026-88260

cve-icon Vulnrichment

Updated: 2026-09-11T16:53:09.874Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T03:16:24.303

Modified: 2026-09-18T19:41:42.593

Link: CVE-2026-88260

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:57:14Z

Weaknesses
  • CWE-1286

    Improper Validation of Syntactic Correctness of Input

  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel