← Vulnerability feed

Vulnerability record · CVE-2022-46768 · published 15 December 2022

CVE-2022-46768: Zabbix Web Service Report Generation arbitrary file read

Zabbix · Web Service Report Generation

Zabbix Web Service Report Generation listens on port 10053 and fails to validate URL parameters before reading files, allowing arbitrary file reads. Because the service is network-reachable and needs no credentials, exposed instances can leak sensitive local files to unauthenticated attackers.

5.9 CVSS 3.1 Medium EPSS 48% · top 1.2% CWE-20 · Improper input validation
5.9CVSS 3.1 base score
48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityUnauthenticated network-reachable arbitrary file read with a high EPSS percentile, though no KEV listing or known exploit reference.

What it is

Zabbix Web Service Report Generation listens on port 10053 and fails to validate URL parameters before reading files, allowing arbitrary file reads. Because the service is network-reachable and needs no credentials, exposed instances can leak sensitive local files to unauthenticated attackers.

Impact

An attacker can read arbitrary files accessible to the Zabbix web service process, potentially exposing configuration, credentials or other sensitive data. There is no write or code execution impact per the CVSS vector, which rates confidentiality high and integrity/availability none.

Attack surface

Reached over the network via the service on port 10053; the CVSS vector shows no privileges required and no user interaction. The flaw is triggered by crafted URL parameters passed to the report generation service.

Exploitation

Not listed in CISA KEV and no public exploit references are provided, but EPSS is high at roughly 0.478 (98.8th percentile), indicating elevated likelihood of attempted exploitation.

What to do

  • Apply the vendor patch referenced in ZBX-22087 as the first action.
  • Restrict network access to port 10053 so only trusted report-generation clients can reach it.
  • Run the Zabbix web service under a least-privilege account with no access to sensitive files.
  • Monitor vendor advisories for updated fixed versions and confirm the deployed build is patched.

Detection

  • Monitor requests to port 10053 for URL parameters containing file paths or traversal sequences.
  • Alert on unexpected file reads by the Zabbix web service process outside its expected report directories.
  • Review Zabbix web service logs for anomalous or malformed report generation requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-46768 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-32728Zabbix-agent2 improper input validation vulnerabilityThe Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability f…EPSS 0.75%9.8CVE-2023-29453Zabbix-agent2 code injection vulnerabilityTemplates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, …EPSS 0.75%9.8CVE-2022-22704Zabbix-agent2 vulnerabilityThe zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that…EPSS 1.3%9.5CVE-2026-88771Citrix NetScaler Improper Input Validation VulnerabilityImproper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-…KEV9.5CVE-2026-93952Arista velocloud orchestrator improper input validation vulnerabilityVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…KEVEPSS 0.90%8.8CVE-2019-1068Microsoft SQL Server improper input validation remote code executionMicrosoft SQL Server mishandles processing of internal functions, allowing an authenticated remote attacker to execute code on the database server. T…KEVEPSS 58%analysed5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed9.3CVE-2026-12569PTC Windchill PDMlink and FlexPLM deserialization RCEPTC Windchill PDMlink and FlexPLM contain a deserialization of untrusted data flaw (also classified as improper input validation) that allows remote …KEVEPSS 46%analysed

Source: NIST National Vulnerability Database (record CVE-2022-46768), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.