Vulnerability record · CVE-2022-46768 · published 15 December 2022
CVE-2022-46768: Zabbix Web Service Report Generation arbitrary file read
Zabbix · Web Service Report Generation
Zabbix Web Service Report Generation listens on port 10053 and fails to validate URL parameters before reading files, allowing arbitrary file reads. Because the service is network-reachable and needs no credentials, exposed instances can leak sensitive local files to unauthenticated attackers.
Description
Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network-reachable arbitrary file read with a high EPSS percentile, though no KEV listing or known exploit reference.
What it is
Zabbix Web Service Report Generation listens on port 10053 and fails to validate URL parameters before reading files, allowing arbitrary file reads. Because the service is network-reachable and needs no credentials, exposed instances can leak sensitive local files to unauthenticated attackers.
Impact
An attacker can read arbitrary files accessible to the Zabbix web service process, potentially exposing configuration, credentials or other sensitive data. There is no write or code execution impact per the CVSS vector, which rates confidentiality high and integrity/availability none.
Attack surface
Reached over the network via the service on port 10053; the CVSS vector shows no privileges required and no user interaction. The flaw is triggered by crafted URL parameters passed to the report generation service.
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is high at roughly 0.478 (98.8th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Apply the vendor patch referenced in ZBX-22087 as the first action.
- Restrict network access to port 10053 so only trusted report-generation clients can reach it.
- Run the Zabbix web service under a least-privilege account with no access to sensitive files.
- Monitor vendor advisories for updated fixed versions and confirm the deployed build is patched.
Detection
- Monitor requests to port 10053 for URL parameters containing file paths or traversal sequences.
- Alert on unexpected file reads by the Zabbix web service process outside its expected report directories.
- Review Zabbix web service logs for anomalous or malformed report generation requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.zabbix.com/browse/ZBX-22087 | PatchVendor Advisory |
| https://support.zabbix.com/browse/ZBX-22087 | PatchVendor Advisory |
Track CVE-2022-46768 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-46768), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.