External risk intelligence

ZimaOS Proxy Endpoint Allows Unauthenticated Localhost Access

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-28798

ZimaOS is a web-based operating system designed for edge and home server devices. The vulnerability involves a web interface endpoint that is specifically exposed and reachable when the device is deployed using common remote access methods like Cloudflare Tunnels, making the management interface and associated services internet-facing.

Server-Side Request Forgery

Zimaspace Zimaos

before 1.5.3

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability in ZimaOS, an operating system for specific devices and systems, which could allow unauthenticated access to internal services if the device is accessible from the internet. The issue has been addressed in version 1.5.3.

  • Allows unauthorized access to internal systems.
  • Exposes sensitive local services to the internet.
  • Confirm relevance and exposure for ZimaOS devices.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by accessing a ZimaOS device that is exposed to the internet through a Cloudflare Tunnel. The attacker would then interact with a proxy endpoint in the web interface, which allows them to send requests to internal services on the device. This could grant unauthenticated access to sensitive local services.

  • Internet access to the device required.
  • Proxy endpoint in the web interface.
  • Unauthenticated access to local services.

Live Threat

Current exploitation, exposure, and threat context

When ZimaOS is configured with an externally reachable domain via Cloudflare Tunnel, an unauthenticated attacker could exploit a proxy endpoint in the web interface to access internal-only services. This could lead to unauthorized control over local services and system data when the product is reachable from the internet.

  • System data and sensitive local services.
  • Abuse of a proxy endpoint via external domain.
  • Unauthenticated access to internal services.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts ZimaOS installations, particularly those exposed externally via Cloudflare Tunnels. Infrastructure or platform teams managing Zima devices are likely responsible for addressing this. The first practical step is to identify all ZimaOS deployments, confirm their external reachability and business criticality, and then locate the accountable system owner to plan remediation based on risk.

  • Platform/Infrastructure teams own the issue.
  • Verify external reachability and asset criticality.
  • Plan and execute remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is ZimaOS?

ZimaOS is a specialized operating system built as a fork of CasaOS. It is primarily designed to power edge computing and home server hardware, as well as x86-64 systems that utilize UEFI. It provides a web-based management interface that allows users to easily manage files, containers, and applications running on their local device.

How does CVE-2026-28798 work?

This vulnerability is classified as Server-Side Request Forgery (CWE-918). It occurs because a specific proxy endpoint in the ZimaOS web interface fails to validate requests, allowing them to be redirected to internal services. Essentially, an attacker can use this interface to trick the system into talking to its own internal, private services that are not meant to be accessed from the outside.

Do I need a Cloudflare Tunnel for this to be triggered?

Yes, the vulnerability specifically requires that the ZimaOS device be reachable from the internet. The proxy endpoint is abused via an externally reachable domain, such as those provided by Cloudflare Tunnels. If your ZimaOS device is only accessible on a local, private network without any external internet-facing tunnels or gateways, this specific attack path is not currently active.

Is my device at risk based on Halo Surface Signal?

According to Halo Surface Signal, this vulnerability is highly relevant for devices that are internet-facing. Because ZimaOS is a web-based platform often used for remote management, using tools like Cloudflare Tunnels makes the management interface public. If your instance is reachable from the internet, you should consider it exposed to the risk of unauthorized access to internal system services.

How do I secure my ZimaOS installation?

The most effective way to resolve this is to update your software to version 1.5.3 or later, which includes the necessary patch for the proxy endpoint. Before applying the update, verify which of your ZimaOS devices are accessible from the internet. After confirming your inventory and risk profile, prioritize updating any devices that have external connectivity to eliminate the potential for unauthenticated access.

References