Zabbix 7.2.x < 7.2.15 Multiple Vulnerabilities

high Web App Scanning Plugin ID 115516

Synopsis

Zabbix 7.2.x < 7.2.15 Multiple Vulnerabilities

Description

According to its self-reported version number, the version of Zabbix running on the remote host is 6.0.x prior to 6.0.44, or 7.0.x prior to 7.0.23, or 7.2.x prior to 7.2.15, or 7.4.x prior to 7.4.7. It is, therefore, affected by multiple vulnerabilities :

- A blind, read-only SQL injection vulnerability in include/classes/api/CApiService.php, as a low privilege user with API access can execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based techniques, potentially leading to session identifier disclosure and administrator account compromise. (CVE-2026-23921)

- An OS command injection vulnerability, as host and event action script input is validated with an administrator-defined regex that runs in multiline mode. If the ^ and $ anchors are used, an injected newline lets authenticated users bypass the check and inject shell commands. (CVE-2026-23920)

- An insufficient isolation of the JavaScript (Duktape) execution context on the Zabbix server and proxy, as contexts used by script items, JavaScript preprocessing and webhooks are reused for performance reasons. This can lead to a confidentiality loss where a regular (non-super) administrator leaks data for hosts they do not have access to. (CVE-2026-23919)

- An unsafe reflection vulnerability, as an unauthenticated attacker can exploit the frontend 'validate' action to blindly instantiate arbitrary PHP classes. (CVE-2026-23923)

- An argument injection vulnerability in the Agent 2 Docker plugin, which does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon, allowing an attacker able to invoke Agent 2 to read arbitrary files from running Docker containers. (CVE-2026-23924)

Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Zabbix version 7.2.15 or later.

See Also

https://www.zabbix.com/security_advisories?query=ZBV-2026-03-24-1

https://www.zabbix.com/security_advisories?query=ZBV-2026-03-24-2

https://www.zabbix.com/security_advisories?query=ZBV-2026-03-24-3

https://www.zabbix.com/security_advisories?query=ZBV-2026-03-24-4

https://www.zabbix.com/security_advisories?query=ZBV-2026-03-24-5

Plugin Details

Severity: High

ID: 115516

Type: Version Based

Published: 9/23/2026

Updated: 9/23/2026

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.19

CVSS v2

Risk Factor: High

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-23920

CVSS v3

Risk Factor: High

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS Score Source: CVE-2026-23920

CVSS v4

Risk Factor: High

Base Score: 8.7

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-23921

Vulnerability Information

CPE: cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*

Exploit Ease: No known exploits are available

Patch Publication Date: 3/24/2026

Vulnerability Publication Date: 3/23/2026

Reference Information

CVE: CVE-2026-23919, CVE-2026-23920, CVE-2026-23921, CVE-2026-23923, CVE-2026-23924