Executive brief
Zenius EMS is an integrated IT infrastructure management platform used by enterprises to monitor and manage cloud environments, data centers, and distributed systems. A combination of authentication bypass and input validation flaws allows attackers to include remote code without proper authentication, potentially leading to unauthorized system access and operational compromise.
Technical details
This vulnerability combines an authentication bypass via alternate path/channel with improper input validation (CWE-20/CWE-287). The vulnerability resides in Zenius EMS 8.0 through Build 109 in the OAM (Operations and Administration Module). The flaws allow an unauthenticated or weakly-authenticated attacker with network access to the EMS interface to bypass authentication checks and inject remote code for inclusion, resulting in remote code execution. No patch status is currently documented.
Affected products
- Brainzco Zenius EMS 8.0 through Build 109
Timeline
- 2026-09-11: disclosed