CVE Vulnerabilities

CVE-2024-36466

Authentication Bypass by Spoofing

Published: Nov 28, 2024 | Modified: Oct 08, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions.

Weakness

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Affected Software

NameVendorStart VersionEnd Version
ZabbixZabbix6.0.0 (including)6.0.32 (excluding)
ZabbixZabbix6.4.0 (including)6.4.17 (excluding)
ZabbixZabbix7.0.0 (including)7.0.0 (including)
ZabbixUbuntufocal*
ZabbixUbuntutrusty/esm*
ZabbixUbuntuupstream*

References