CVE-2024-36466: Zabbix
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions.
Affected products
- Zabbix Zabbix: from 6.0.0, before 6.0.32 (fixed in 6.0.32); from 6.4.0, before 6.4.17 (fixed in 6.4.17); version 7.0.0 only
Published 2024-11-28. Last modified 2026-06-17.