Description
Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell script on the application server in the context of the application user.
References (1)
Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/paalbra/zabbix-zbxsec-7
Scores
CVSS v3
7.2
EPSS
0.0404
EPSS Percentile
89.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (1)
zabbix/zabbix
4.0.0 - 4.0.34
Published
Jan 27, 2022
Tracked Since
Feb 18, 2026