Beyond weak credentials, Zabbix itself has shipped authentication-bypass and session-handling vulnerabilities, so against an affected version an attacker reaches authenticated functionality without valid credentials. The flaw classes include bugs in the JSON-RPC and frontend request handling that exposed actions meant to require login, and weaknesses in the SAML/SSO and session validation logic that let a request be treated as an authenticated (sometimes privileged) user. The impact is access to the API/UI, which then chains into the platform's own code-execution features (scripts, items) or into direct exploitation. These are version-specific, so fingerprinting the build and matching the advisory is the method.
# fingerprint first (the applicable bypass is version-specific)
curl -sk https://<target>/zabbix/api_jsonrpc.php -H 'Content-Type: application/json-rpc' \
-d '{"jsonrpc":"2.0","method":"apiinfo.version","params":{},"id":1}'
# the bypass itself is specific to the version/flaw (e.g. crafted JSON-RPC calls that
# reach protected methods, or SAML/session handling that yields an authenticated session);
# match the Zabbix build to the advisory for the exact request.
Exploitation notes#
- The entry is version-specific:
apiinfo.versiongives the build unauthenticated, which maps to the applicable auth-bypass or session flaw; there is no single universal bypass. - SAML/SSO handling bugs are notable because they can yield an authenticated, sometimes admin, session; where SSO is configured, assess it against the version.
- A bypass that reaches the API is as good as a login for what follows: enumerate hosts/macros and drive code execution via scripts or items.
- Where no bypass applies, fall back to credentials (default/weak) and session theft.