Vulnerabilities
90 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-23929 | Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation that traversed the prototype chain. NVD description · AI analysis pending | 8.5 group max | <1% |
| — | ||
| CVE-2026-23921 | A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL sele A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based techniques, potentially leading to session identifier disclosure and administrator account compromise. NVD description · AI analysis pending | 8.7 group max | 3% |
| — | ||
| CVE-2026-23925 | An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions. NVD description · AI analysis pending | 5.1 | <1% |
| — | ||
| CVE-2025-27232 +1 in the same advisory: …49643 | An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss. An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss. NVD description · AI analysis pending | 6.8 group max | <1% |
| — | ||
| CVE-2025-49641 | A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refresh action and therefore still retrieve a A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refresh action and therefore still retrieve a list of active problems. NVD description · AI analysis pending | 5.1 group max | <1% |
| — | ||
| CVE-2025-27240 +1 in the same advisory: …27238 | A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field. A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field. NVD description · AI analysis pending | 7.5 group max | 1% |
| — | ||
| CVE-2024-36465 | SQL Injection in Zabbix API via groupBy Parameter Zabbix contains a SQL injection flaw (CWE-89) in include/classes/api/CApiService.php, where the groupBy parameter is passed into SQL queries without proper sanitization. Any low-privilege (regular) Zabbix user with API access can exploit it by sending crafted groupBy values through the API, triggering arbitrary SQL command execution. Successful exploitation gives an attacker high-impact read and write capability against the backend database (CVSS 4.0 rates confidentiality, integrity, and availability impact as High), potentially exposing or modifying monitoring configuration and data. All Zabbix deployments that grant API access to regular users are affected; the provided data does not specify affected version ranges. No public proof-of-concept is known and the flaw is not in CISA KEV, but EPSS assigns a 29.5% probability of exploitation within 30 days (98th percentile), indicating elevated near-term risk. Do: Upgrade Zabbix to the patched release published by the vendor for your branch (the fix corrects SQL handling in include/classes/api/CApiService.php). Until patched, restrict API access to trusted users, limit network exposure of the Zabbix API, and audit which accounts hold API permissions. Check logs for API calls containing unexpected or crafted groupBy parameters as a sign of probing or exploitation. | 8.6 group max | 30% |
| large≈ tens of thousands of internet-reachable Zabbix instances (public scans show tens of thousands of exposed Zabbix frontends/APIs), out of an installed base… | ||
| CVE-2024-36466 | A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions. A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2024-42327 | SQL Injection in Zabbix Frontend User API (CUser.get) CVE-2024-42327 is a SQL injection (CWE-89) in the Zabbix frontend's CUser class, in the addRelatedObjects function, which is reached via the CUser.get API method. Any authenticated non-admin account holding the default User role, or any other role that grants API access, can trigger the flaw simply by calling user.get, with no user interaction required. The CVSS 3.1 score of 9.9 (network vector, low privileges, changed scope, high confidentiality/integrity/availability impact) indicates an attacker could read or alter database contents, potentially compromising the monitoring platform and its data beyond their own account's privileges. All Zabbix deployments whose frontends expose the API to non-admin users are affected, which is the default configuration. Exploitation has not been confirmed: the flaw is not in CISA's KEV catalog and no public PoC is known, but EPSS assigns a very high 78.7% probability of exploitation within 30 days. Do: Upgrade each affected Zabbix instance to the patched release for your branch as specified in Zabbix's security advisory for CVE-2024-42327. As interim mitigation, audit which non-admin users and roles have API access and restrict or disable user.get access for untrusted accounts. Monitor frontend/API logs for anomalous user.get calls and unexpected SQL activity, since exploitation requires only low-privilege API credentials. | 9.9 group max | 79% |
| largetens of thousands of internet-exposed Zabbix frontends, within a deployment base of hundreds of thousands of instances | ||
| CVE-2024-36463 +1 in the same advisory: …22117 | The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal properties of objects. The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal properties of objects. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2024-22122 | Zabbix allows to configure SMS notifications. Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem. NVD description · AI analysis pending | 9.1 group max | 2% |
| — | ||
| CVE-2024-22120 | Zabbix server can perform command execution for configured scripts. Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection. NVD description · AI analysis pending | 8.8 | 77% | PoC |
| — | |
| CVE-2024-22119 | The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section. The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2023-32728 | The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote c The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2023-32725 +1 in the same advisory: …32727 | The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2023-32726 | The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS server. The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS server. NVD description · AI analysis pending | 8.1 | <1% |
| — | ||
| CVE-2023-32723 +1 in the same advisory: …32724 | Request to LDAP is sent before user permissions are checked. Request to LDAP is sent before user permissions are checked. NVD description · AI analysis pending | 9.1 group max | <1% |
| — |