A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions.
{
"unresolved_ranges": [
{
"vendor_product": "zabbix:zabbix",
"cpes": [
"cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "6.4.0"
},
{
"fixed": "6.4.17"
}
],
"source": "CPE_RANGE"
}
]
}{
"cpe": [
"cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*",
"cpe:2.3:a:zabbix:zabbix:7.0.0:-:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "6.0.0"
},
{
"fixed": "6.0.32"
},
{
"introduced": "7.0.0-NA"
},
{
"last_affected": "7.0.0-NA"
}
],
"source": [
"CPE_RANGE",
"CPE_STRING"
]
}
"2026-07-15T06:01:32Z"
[
{
"id": "CVE-2024-36466-304bfe13",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"268532432675997961382533109683550991275",
"77468328968705158713064176216215297941",
"242617437909076284338012963993674069245",
"53988357087650554977707365843443920215",
"128232534528403919384584568266563623737",
"8192478687897789813459981120771879298"
]
},
"source": "https://github.com/zabbix/zabbix/commit/e0ebc610bbe07feec683b36b33b0c7c54d4dfa51",
"target": {
"file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-36466.json"