Authentication

Gaining access to Zabbix is the gateway to its code-execution features and stored credentials, and there are several routes. The default Admin superadmin account ships with the password zabbix and is frequently unchanged. Weak passwords and the absence of a strong policy make brute force and spraying effective. The built-in guest account, where enabled, grants unauthenticated read access. Specific versions have had API authentication-bypass flaws. And stolen session cookies or API tokens are replayed directly. What matters after access is the account's role: a Super admin unlocks script execution and full configuration, while lesser roles may still enable item-based execution depending on permissions.

bash
# web login and API login both validate the same credentials
Z=https://<target>/zabbix/api_jsonrpc.php
curl -sk $Z -H 'Content-Type: application/json-rpc' \
  -d '{"jsonrpc":"2.0","method":"user.login","params":{"username":"Admin","password":"zabbix"},"id":1}'

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more