---
id: CVE-2026-88260
title: >-
  Authentication bypass using an alternate path or channel and Improper
  validation of syntactic correctness of input vulnerability in Brainzcompany
  Zenius EMS 8.0 allows Remote Code Inclusion.


  This issue affects Zenius EMS 8.0: through OA…
summary: >-
  Authentication bypass using an alternate path or channel and Improper
  validation of syntactic correctness of input vulnerability in Brainzcompany
  Zenius EMS 8.0 allows Remote Code Inclusion.


  This issue affects Zenius EMS 8.0: through OA…
severity: high
cvss: 8.7
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-288
  - CWE-1286
vendor: Brainzcompany
product: Zenius EMS 8.0
affected:
  - zenius_ems_8.0 <= OAM (Build 109)
published: '2026-09-11'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:41:42.593'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88260'
references:
  - url: 'https://www.brainz.co.kr/Features'
    label: 09832df1-09c1-45b4-8a85-16c601d30feb
tags:
  - nvd
  - cve.org
epss: 0.00319
epssPercentile: 0.22126
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-11T16:48:48.098012Z'
cvssSource: cna
ingestedAt: '2026-09-14T00:35:28.536Z'
---

## Overview

Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion.

This issue affects Zenius EMS 8.0: through OAM (Build 109).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
