Vulnerabilities
Vulnerable Software
Zabbix:  >> Zabbix  >> 7.2.14  Security Vulnerabilities
A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based techniques, potentially leading to session identifier disclosure and administrator account compromise.
CVSS Score
8.7
EPSS Score
0.035
Published
2026-03-24
Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands.
CVSS Score
7.7
EPSS Score
0.003
Published
2026-03-24


Contact Us

Shodan ® - All rights reserved