Beyond specific exploits, how Zabbix is deployed decides how exposed it is. Two configuration weaknesses recur. The frontend and API are frequently reachable from untrusted networks (the internet, or a flat internal network), which exposes the login, the version, and the guest/default-credential surface to anyone. And the role and user-group model is often too permissive: accounts are granted the Super-admin role or the script/item permissions that lead to code execution when they do not need them, so compromising an ordinary account yields far more than its purpose warranted. These are not single-shot exploits but the conditions that make the other attacks reachable and impactful.
Subtopics#
- Exposed web interface: the frontend and API reachable from untrusted networks.
- Weak permissions: over-privileged roles and user groups.