Executive brief
ZimaOS is an operating system used to manage Zima personal cloud devices and x86-64 servers. A security flaw allows remote attackers to bypass security controls and access private internal services and sensitive configuration data if the device is connected to the internet via a Cloudflare Tunnel. This could lead to unauthorized access to administrative interfaces, data theft, or full system compromise.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the /v1/sys/proxy endpoint of ZimaOS's web interface. When a ZimaOS instance is made reachable from the internet using a Cloudflare Tunnel, an unauthenticated remote attacker can abuse this endpoint to proxy requests to services bound to localhost or internal-only IP addresses. This bypasses intended network isolation, granting access to sensitive internal-only endpoints, user management APIs, and device configurations. The vulnerability is tracked as CWE-918 and has been addressed in version 1.5.3.
Affected products
- IceWhaleTech ZimaOS < 1.5.3
Timeline
- 2026-03-31: advisory: Vendor advisory published on GitHub
- 2026-04-03: disclosed: CVE published to NVD
- 2026-05-05: patched: Version 1.5.3 released