CVE-2026-21891 (CNNVD-202601-1468)
中文标题:
ZimaOS 安全漏洞
英文标题:
ZimaOS has Authentication Bypass via System-Level Username
漏洞描述
中文描述:
ZimaOS是IceWhaleTech的一个开源的操作系统项目,旨在提供一个轻量级、高性能、安全的操作系统环境。 ZimaOS 1.5.0及之前版本存在安全漏洞,该漏洞源于密码验证不当,可能导致未经授权的访问。
英文描述:
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions up to and including 1.5.0, the application checks the validity of the username but appears to skip, misinterpret, or incorrectly validate the password when the provided username matches a known system service account. The application's login function fails to properly handle the password validation result for these users, effectively granting authenticated access to anyone who knows one of these common usernames and provides any password. As of time of publication, no known patched versions are available.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| IceWhaleTech | ZimaOS | <= 1.5.0 | - | - |
cpe:2.3:a:icewhaletech:zimaos:<=_1.5.0:*:*:*:*:*:*:*
|
| zimaspace | zimaos | * | - | - |
cpe:2.3:o:zimaspace:zimaos:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
3.1 (cna)
CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2026-21891 |
2026-01-09 02:02:08 | 2026-01-12 02:12:38 |
| NVD | nvd_CVE-2026-21891 |
2026-01-09 03:00:10 | 2026-01-12 02:28:17 |
| CNNVD | cnnvd_CNNVD-202601-1468 |
2026-01-11 06:15:10 | 2026-01-12 02:38:14 |
版本与语言
安全公告
变更历史
查看详细变更
- affected_products_count: 1 -> 2
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202601-1468
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']