ZimaOS <= 1.5.0 contains a broken authentication caused by improper password validation for known system service accounts in the login function, letting attackers authenticate with any password for these accounts, exploit requires knowledge of common usernames.
id: CVE-2026-21891
info:
name: ZimaOS - Authentication Bypass
author: DhiyaneshDk
severity: c
...