CVE-2026-23927: Zabbix

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a named session.

Affected products

  • Zabbix Zabbix: from 6.0.0, before 6.0.45 (fixed in 6.0.45); from 7.0.0, before 7.0.24 (fixed in 7.0.24); from 7.4.0, before 7.4.8 (fixed in 7.4.8)

Published 2026-05-06. Last modified 2026-09-18.