Junglewise Threat Intelligence

CVE-2026-28798: IceWhaleTech ZimaOS SSRF in proxy endpoint

CVE-2026-28798 · Severity: critical · CVSS 9 · Published 2026-04-03

Executive brief

ZimaOS is an operating system used to manage Zima personal cloud devices and x86-64 servers. A security flaw allows remote attackers to bypass security controls and access private internal services and sensitive configuration data if the device is connected to the internet via a Cloudflare Tunnel. This could lead to unauthorized access to administrative interfaces, data theft, or full system compromise.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the /v1/sys/proxy endpoint of ZimaOS's web interface. When a ZimaOS instance is made reachable from the internet using a Cloudflare Tunnel, an unauthenticated remote attacker can abuse this endpoint to proxy requests to services bound to localhost or internal-only IP addresses. This bypasses intended network isolation, granting access to sensitive internal-only endpoints, user management APIs, and device configurations. The vulnerability is tracked as CWE-918 and has been addressed in version 1.5.3.

Affected products

  • IceWhaleTech ZimaOS < 1.5.3

Timeline

  • 2026-03-31: advisory: Vendor advisory published on GitHub
  • 2026-04-03: disclosed: CVE published to NVD
  • 2026-05-05: patched: Version 1.5.3 released

References