CVE-2021-46088

HIGH

Zabbix <5.0 - Remote Code Execution

Title source: llm
STIX 2.1

Description

Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell script on the application server in the context of the application user.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/paalbra/zabbix-zbxsec-7

Scores

CVSS v3 7.2
EPSS 0.0404
EPSS Percentile 89.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
zabbix/zabbix 4.0.0 - 4.0.34
Published Jan 27, 2022
Tracked Since Feb 18, 2026