CVE-2021-27927
Zabbix Server vulnerability analysis and mitigation

Overview

In Zabbix from versions 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, a critical Cross-Site Request Forgery (CSRF) vulnerability was identified in the CControllerAuthenticationUpdate controller. The vulnerability exists due to the lack of CSRF protection mechanism, where the controller explicitly disables SID validation in the init() method. An attacker can exploit this vulnerability without knowing Zabbix user login credentials, requiring only the correct Zabbix URL and contact information of an existing user with sufficient privileges (NVD, Horizon3).

Technical details

The vulnerability stems from the CControllerAuthenticationUpdate controller having token validation turned off. Additionally, any parameters submitted in a request body via POST could equivalently be submitted as URL query parameters via GET. The vulnerability has a CVSS v3.1 base score of 8.8 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The attack is exploitable even with the default SameSite=Lax cookie protection in place, as it leverages GET requests that trigger top-level navigation (Horizon3).

Impact

The impact of this vulnerability is severe as it can lead to full takeover of the Zabbix administrator account. Once administrative access is gained, attackers can access detailed information about other devices on the network and execute arbitrary commands on the Zabbix server. In certain configurations, attackers can also execute arbitrary commands on hosts being monitored by Zabbix. At the time of discovery, approximately 20,000 instances of Zabbix were exposed on the Internet (Horizon3).

Exploitability

The vulnerability requires user interaction but is relatively straightforward to exploit. An attacker needs to set up a malicious LDAP server accessible to the target Zabbix application, create a web page containing the forged cross-site request, and convince the Zabbix administrator to click on a malicious link. The attack is not blind, as the attacker can verify success through the Zabbix application's LDAP server connection test (Horizon3).

Mitigation and workarounds

The vulnerability is fixed in Zabbix versions 4.0.28rc1, 5.0.8rc1, 5.2.4rc1, and 5.4.0alpha1. Organizations should upgrade to these versions or newer to protect against this vulnerability. The fix was released on February 22, 2021, after being disclosed to the vendor on January 3, 2021 (Horizon3).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Alpine

Fixed

edge

zabbix: 5.2.6-r0

Fixed

v3.18

zabbix: 5.2.6-r0

Fixed

v3.19

zabbix: 5.2.6-r0

Fixed

v3.20

zabbix: 5.2.6-r0

Fixed

v3.21

zabbix: 5.2.6-r0

Fixed

v3.22

zabbix: 5.2.6-r0

Fixed

v3.23

zabbix: 5.2.6-r0

Fixed

Arch Linux

Fixed

rolling

zabbix-frontend-php: 5.2.6-1

Fixed

SourceThis report was generated using AI

Related Zabbix Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23935MEDIUM6.8
  • Zabbix Server logoZabbix Server
  • zabbix
NoYesAug 18, 2026
CVE-2026-23937MEDIUM6
  • Zabbix Server logoZabbix Server
  • zabbix
NoYesAug 18, 2026
CVE-2026-59781MEDIUM5.4
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoYesAug 18, 2026
CVE-2026-23934MEDIUM5.1
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoNoAug 18, 2026
CVE-2026-23938LOW2.1
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management