Zabbix API Vulnerability: High-Severity SQL Injection Threatens Network Monitoring Security
ID: 4fdaa0e0-6e51-548e-9202-3951be98b3c2
STIX ID: report--4fdaa0e0-6e51-548e-9202-3951be98b3c2
Feed Name: securityonline.info
A high-severity (CVSS 8.7) blind SQL injection vulnerability (CVE-2026-23921) in Zabbix's API component (include/classes/api/CApiService.php) via the sortfield parameter allows authenticated users with API permissions to perform time-based SQL selects to exfiltrate sensitive data—potentially exposing session IDs and enabling privilege escalation. Affected versions include Zabbix 7.0.0–7.0.21, 7.2.0–7.2.14, and 7.4.0–7.4.5; Zabbix released fixes (7.0.22, 7.2.15, 7.4.6) and recommends applying patches and restricting API access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
