CVE-2026-23924
- EPSS 0.25%
- Veröffentlicht 24.03.2026 18:30:00
- Zuletzt bearbeitet 18.09.2026 17:02:40
Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting the...
CVE-2026-23923
- EPSS 0.29%
- Veröffentlicht 24.03.2026 18:29:23
- Zuletzt bearbeitet 10.09.2026 21:16:44
An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.
CVE-2026-23921
- EPSS 0.24%
- Veröffentlicht 24.03.2026 18:28:41
- Zuletzt bearbeitet 10.09.2026 21:13:20
A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an atta...
CVE-2026-23920
- EPSS 0.25%
- Veröffentlicht 24.03.2026 18:27:52
- Zuletzt bearbeitet 10.09.2026 21:15:39
Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check an...
- EPSS 0.15%
- Veröffentlicht 24.03.2026 18:26:43
- Zuletzt bearbeitet 18.09.2026 17:07:18
For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts th...
CVE-2026-23925
- EPSS 0.26%
- Veröffentlicht 06.03.2026 08:24:15
- Zuletzt bearbeitet 05.06.2026 17:05:16
An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not su...
CVE-2025-49643
- EPSS 0.33%
- Veröffentlicht 01.12.2025 13:05:33
- Zuletzt bearbeitet 26.09.2026 00:10:00
An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service.
CVE-2025-49642
- EPSS 0.12%
- Veröffentlicht 01.12.2025 13:03:38
- Zuletzt bearbeitet 29.04.2026 01:00:01
Library loading on AIX Zabbix Agent builds can be hijacked by local users with write access to the /home/cecuser directory.
CVE-2025-27232
- EPSS 0.28%
- Veröffentlicht 01.12.2025 12:55:51
- Zuletzt bearbeitet 26.09.2026 00:10:00
An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.
CVE-2025-49641
- EPSS 0.27%
- Veröffentlicht 03.10.2025 11:29:26
- Zuletzt bearbeitet 08.10.2025 14:55:00
A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refresh action and therefore still retrieve a list of active problems.