# CVE-2026-88260

## Summary

- **CVE ID:** CVE-2026-88260
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-288, CWE-1286
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 11, 2026

## Description

Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion.

This issue affects Zenius EMS 8.0: through OAM (Build 109).

## Affected Products

- Brainzcompany — Zenius EMS 8.0 (0)

## References

- [CNA](https://www.brainz.co.kr/Features)

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._