CVE-2026-28798Disclosure(zimaspace / zimaos)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch zimaspace zimaos systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. Prior to version 1.5.3, a proxy endpoint (/v1/sys/proxy) exposed by ZimaOS's web interface can be abused (via an externally reachable domain using a Cloudflare Tunnel) to make requests to internal localhost services. This results in unauthenticated access to internal-only endpoints and sensitive local services when the product is reachable from the Internet through a Cloudflare Tunnel. This issue has been patched in version 1.5.3.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zimaos

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-03); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
zimaos

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-04-03: 2Mentions · 2026-04-04: 2PoC Mentioned / Linked · 2026-04-04: 1Patch / Workaround · 2026-04-03: 1Technical Details · 2026-04-03: 2Technical Details · 2026-04-04: 204-0304-04
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-032
Disclosure1Patch1
2026-04-042
Disclosure2
Full discourse4 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-28798 - Critical ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. Prior to version 1.5.3, a proxy endpoint (/v1/sys/proxy) exposed by ZimaOS's web interface c... https://www.thehackerwire.com/vulnerability/CVE-2026-28798/ https://t.co/MD4bAZ7Meb

    Post summary

    A critical vulnerability (CVE-2026-28798) affecting ZimaOS’s proxy endpoint is disclosed, with reference to an external article for further details.

    0000062
    164 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Disclosure

    🚨 Critical ZimaOS Vulnerability (#CVE-2026-28798): How a Cloudflare Tunnel Exposed Internal Networks to Unauthenticated SSRF + Video https://undercodetesting.com/critical-zimaos-vulnerability-cve-2026-28798-how-a-cloudflare-tunnel-exposed-internal-networks-to-unauthenticated-ssrf-video/ Educational Purposes!

    Post summary

    A new CVE-2026-28798 affecting ZimaOS was disclosed, demonstrating that a Cloudflare Tunnel can expose internal networks through unauthenticated SSRF, with an accompanying video showing the issue.

    0000050
    464 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-28798: CRITICAL] ZimaOS, a fork of CasaOS, fixed a security issue in version 1.5.3 related to unauthorized access to internal services through its web interface proxy endpoint (/v1/sys/proxy).#cve,CVE-2026-28798,#cybersecurity https://cvefind.com/CVE-2026-28798

    Post summary

    ZimaOS released version 1.5.3 to patch CVE-2026-28798, which allowed unauthorized access to internal services via its web interface proxy endpoint.

    0000046
    619 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-28798: Arbitrary internal service acces... ZimaOS /v1/sys/proxy endpoint turns Cloudflare Tunnels into SSRF goldmines - localhost services exposed to internet att... https://zerodaysignal.com/vulnerability/CVE-2026-28798 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑28798, a Server Side Request Forgery flaw in ZimaOS that allows attackers to reach internal services via Cloudflare Tunnels, providing basic disclosure details without PoC, exploitation, or patch information.

    0000075
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSzimaspacezimaos---

Explore more