CRITICAL
IceWhaleTech
CVE published 2026-04-03
CVE-2026-28798
A critical vulnerability was discovered in ZimaOS, a fork of CasaOS, used in Zima devices and x86-64 systems with UEFI. The issue, tracked as CVE-2026-28798, allows an attacker to abuse a proxy endpoint exposed by ZimaOS's web interface to make requests to internal localhost services. This can lead to unauthenticated access to internal-only endpoints and sensitive local services when the product is reacha [truncated]