๐Ÿ” CVE Alert

CVE-2026-28798

CRITICAL 9.1

Arbitrary internal service access via /v1/sys/proxy when Cloudflare Tunnel is enabled on ZimaOS

CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
13th

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. Prior to version 1.5.3, a proxy endpoint (/v1/sys/proxy) exposed by ZimaOS's web interface can be abused (via an externally reachable domain using a Cloudflare Tunnel) to make requests to internal localhost services. This results in unauthenticated access to internal-only endpoints and sensitive local services when the product is reachable from the Internet through a Cloudflare Tunnel. This issue has been patched in version 1.5.3.

CWE CWE-918
Vendor icewhaletech
Product zimaos
Published Apr 3, 2026
Last Updated Apr 6, 2026
Stay Ahead of the Next One

Get instant alerts for icewhaletech zimaos

Be the first to know when new critical vulnerabilities affecting icewhaletech zimaos are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

IceWhaleTech / ZimaOS
< 1.5.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/IceWhaleTech/ZimaOS/security/advisories/GHSA-vqqj-f979-8c8m github.com: https://github.com/IceWhaleTech/ZimaOS/releases/tag/1.5.3