CVE-2021-46088: High severity zabbix server vulnerability
Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell script on the application server in the context of the application user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-46088?
The severity of CVE-2021-46088 is high with a severity value of 7.2.
Which versions of Zabbix are affected by CVE-2021-46088?
Zabbix versions 4.0 LTS (4.0.0 - 4.0.34), 4.2 (4.2.0 - 4.2.8), 4.4 (4.4.0 - 4.4.11), and 5.0 LTS (5.0.0 - 5.0.20) are affected by CVE-2021-46088.
What is the vulnerability in Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS?
The vulnerability is a Remote Code Execution (RCE) where any user with the "Zabbix Admin" role can run custom shell script on the application server in the context of the application user.
Who can exploit the vulnerability in CVE-2021-46088?
Any user with the "Zabbix Admin" role can exploit the vulnerability in CVE-2021-46088.
How can I fix the vulnerability in Zabbix?
To fix the vulnerability in Zabbix, you should upgrade to a version that is not affected by CVE-2021-46088.