CVE-2026-23921
published 2026-03-24CVE-2026-23921: A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL…
PriorityP355high8.7CVSS 4.0
AVNACLATNPRLUINVCHVIHVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.24%
15.2th percentile
A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based techniques, potentially leading to session identifier disclosure and administrator account compromise.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zabbix | < zabbix 1:7.0.22+dfsg-1 (forky) | zabbix 1:7.0.22+dfsg-1 (forky) |
| zabbix | zabbix | >= 0 < 1:7.0.22+dfsg-1~deb13u1 | 1:7.0.22+dfsg-1~deb13u1 |
| zabbix | zabbix | >= 0 < 1:7.0.22+dfsg-1 | 1:7.0.22+dfsg-1 |
| zabbix | zabbix | 7.0.0 – 7.0.21 | — |
| zabbix | zabbix | 7.2.0 – 7.2.14 | — |
| zabbix | zabbix | 7.4.0 – 7.4.5 | — |
CVSS provenance
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.7HIGH
vendor_debian8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2026-23921: zabbix - A low privilege Zabbix user with API access can exploit a blind SQL injection vu...
vendor_debian·2026·CVSS 8.7
CVE-2026-23921 [HIGH] CVE-2026-23921: zabbix - A low privilege Zabbix user with API access can exploit a blind SQL injection vu...
A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based techniques, potentially leading to session identifier disclosure and administrator account compromise.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:7.0.22+dfsg-1)
sid: resolved (fixed in 1:7.0.22+dfsg-1)
trixie: resolved (fixed in 1:7.0.22+dfsg-1~deb13u1)
OSV
CVE-2026-23921: (A low privilege Zabbix user with API access can exploit a blind SQL in
osv·2026-04-06·CVSS 8.7
CVE-2026-23921 [HIGH] CVE-2026-23921: (A low privilege Zabbix user with API access can exploit a blind SQL in
(A low privilege Zabbix user with API access can exploit a blind SQL in ...)
OSV
CVE-2026-23921: A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService
osv·2026-03-24·CVSS 8.7
CVE-2026-23921 [HIGH] CVE-2026-23921: A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService
A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based techniques, potentially leading to session identifier disclosure and administrator account compromise.
GHSA
GHSA-j24v-fg24-6mqq: A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService
ghsa_unreviewed·2026-03-24
CVE-2026-23921 [HIGH] CWE-89 GHSA-j24v-fg24-6mqq: A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService
A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based techniques, potentially leading to session identifier disclosure and administrator account compromise.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-23924 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2026-23924 [HIGH] CVE-2026-23924 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23924 :
Zabbix Server vulnerability analysis and mitigation
Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting them via the Docker archive API.
Source : NVD
## 6.1
Score
Published March 24, 2026
Severity MEDIUM
CNA Score 6.1
Affected Technologies
Zabbix Server
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.7
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
zabbix
cpe:2.3:a:zabbix:zabbix
Sources
NVD
Debian 11, 12, 13, 14 No Fix Added at: M
Wiz
CVE-2026-23923 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2026-23923 [HIGH] CVE-2026-23923 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23923 :
Zabbix Server vulnerability analysis and mitigation
An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.
Source : NVD
## 6.9
Score
Published March 24, 2026
Severity MEDIUM
CNA Score 6.9
Affected Technologies
Zabbix Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 22
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:a:zabbix:zabbix
Sources
NVD
Linux No Fix Added at: Mar 26, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable,
Wiz
CVE-2026-23925 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2026-23925 [HIGH] CVE-2026-23925 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23925 :
Zabbix Server vulnerability analysis and mitigation
An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions.
Source : NVD
## 5.1
Score
Published March 6, 2026
Severity MEDIUM
CNA Score 5.1
Affected Technologies
Zabbix Server
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
zabbix
cpe:2.3:a:zabbix:zabbix
Sources
NVD
Wiz
CVE-2026-23920 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2026-23920 [HIGH] CVE-2026-23920 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23920 :
Zabbix Server vulnerability analysis and mitigation
Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands.
Source : NVD
## 7.7
Score
Published March 24, 2026
Severity HIGH
CNA Score 7.7
Affected Technologies
Zabbix Server
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 16.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
zabbix
cpe:2.3:a:zabbix:zabbix
Sources
NVD
Debian 11, 12 No Fix Added at: Mar 29, 2026
De
Wiz
CVE-2026-23921 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2026-23921 [HIGH] CVE-2026-23921 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23921 :
Zabbix Server vulnerability analysis and mitigation
A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based techniques, potentially leading to session identifier disclosure and administrator account compromise.
Source : NVD
## 8.7
Score
Published March 24, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
Zabbix Server
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.7
Exploitation Probability
Wiz
CVE-2026-23919 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2026-23919 [HIGH] CVE-2026-23919 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23919 :
Zabbix Server vulnerability analysis and mitigation
For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A fix has been released that makes the built in Zabbix JavaScript objects read-only, but please be advised that usage of global JavaScript variables is not recommended because their content could be leaked. More information in Zabbix documentation .
Source : NVD
## 7.1
Score
Published March 24, 2026
Severity HIGH
CNA Score 7.1
Affected Technologies
Zabbix Server
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Rel
Bugzilla
CVE-2026-23921 zabbix: Zabbix: Arbitrary database data exfiltration and administrator account compromise via blind SQL injection in API [epel-all]
bugzilla·2026-03-24·CVSS 8.7
CVE-2026-23921 [HIGH] CVE-2026-23921 zabbix: Zabbix: Arbitrary database data exfiltration and administrator account compromise via blind SQL injection in API [epel-all]
CVE-2026-23921 zabbix: Zabbix: Arbitrary database data exfiltration and administrator account compromise via blind SQL injection in API [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-23921 zabbix7.0: Zabbix: Arbitrary database data exfiltration and administrator account compromise via blind SQL injection in API [epel-all]
bugzilla·2026-03-24·CVSS 8.7
CVE-2026-23921 [HIGH] CVE-2026-23921 zabbix7.0: Zabbix: Arbitrary database data exfiltration and administrator account compromise via blind SQL injection in API [epel-all]
CVE-2026-23921 zabbix7.0: Zabbix: Arbitrary database data exfiltration and administrator account compromise via blind SQL injection in API [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
https://support.zabbix.com/browse/ZBX-27640
Bugzilla
CVE-2026-23921 zabbix6.0: Zabbix: Arbitrary database data exfiltration and administrator account compromise via blind SQL injection in API [epel-all]
bugzilla·2026-03-24·CVSS 8.7
CVE-2026-23921 [HIGH] CVE-2026-23921 zabbix6.0: Zabbix: Arbitrary database data exfiltration and administrator account compromise via blind SQL injection in API [epel-all]
CVE-2026-23921 zabbix6.0: Zabbix: Arbitrary database data exfiltration and administrator account compromise via blind SQL injection in API [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
https://support.zabbix.com/browse/ZBX-27640 does not show Zabbix 6.0 as affected.
2026-03-24
Published