CVE-2026-28798 | IceWhaleTech ZimaOS up to 1.5.2 /v1/sys/proxy server-side request forgery (GHSA-vqqj-f979-8c8m)
A vulnerability was found in IceWhaleTech ZimaOS up to 1.5.2. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the file /v1/sys/proxy. This manipulation causes server-side request forgery.
This vulnerability is handled as CVE-2026-28798. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.