A vulnerability has been discovered within Zabbix front end which if configured with SAML could allow a remote unauthenticated attacker to exploit this issue in order to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default).
Affected Version
Zabbix 5.4.0 – 5.4.8, 6.0.0alpha1
Fixed Version
Zabbix 5.4.9rc2, 6.0.0beta1
Remediation
To remediate this vulnerability, apply the updates listed in the ‘Fixed Version’ section to appropriate products or if an immediate update is not possible, follow the presented below workarounds.
Workaround
Where immediate patching is not possible it is possible to remediation this issue by disabling SAML authentication. Please be aware of the side effects of disabling SAML before performing this action if you rely on SAML for authentication.
References
What kills new CISOs in their first 90 days – it’s not attackers.
The pen test report. The risk register. The green dashboard. They feel like facts. They’re not. They’re a record of someone else’s decisions, at a point…
CVE-2026-33727 – When “Low Privilege” Isn’t Low Enough: A Pi-hole LPE Story
Pi-hole’s pihole user is low-privileged. It’s configured with nologin. It looks contained. It isn’t. Here’s how a writable file and a trusting root process combine into…
Proof of Human solves the bot problem. It doesn’t solve the people problem.
World ID can prove a real human is behind an account. It can’t prove that human hasn’t already been phished, vished, or bribed. The biggest breaches…