CVE-2024-36467: Authentication privilege escalation via user groups due to missing authorization checks
An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is enough to be able to add themselves to any group (e.g.: Zabbix Administrators), except to groups that are disabled or having restricted GUI access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36467?
CVE-2024-36467 has been classified as a moderate severity vulnerability.
How do I fix CVE-2024-36467?
To fix CVE-2024-36467, upgrade Zabbix to the latest version where the vulnerability has been addressed.
Who is affected by CVE-2024-36467?
CVE-2024-36467 affects Zabbix users with API access to the user.update endpoint.
What kind of access does CVE-2024-36467 exploit?
CVE-2024-36467 exploits authenticated user access to grant themselves additional group permissions.
What are the versions of Zabbix impacted by CVE-2024-36467?
CVE-2024-36467 affects Zabbix versions from 5.0.0 to 5.0.43, 6.0.0 to 6.0.33, 6.4.0 to 6.4.18, and 7.0.0 to 7.0.2.