CVE Vulnerabilities

CVE-2024-36466

Authentication Bypass by Spoofing

Published: Nov 28, 2024 | Modified: Oct 08, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions.

Weakness

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Affected Software

Name Vendor Start Version End Version
Zabbix Zabbix 6.0.0 (including) 6.0.32 (excluding)
Zabbix Zabbix 6.4.0 (including) 6.4.17 (excluding)
Zabbix Zabbix 7.0.0 (including) 7.0.0 (including)
Zabbix Ubuntu focal *
Zabbix Ubuntu trusty/esm *
Zabbix Ubuntu upstream *

References