Uploaded image for project: 'ZABBIX BUGS AND ISSUES'
  1. ZABBIX BUGS AND ISSUES
  2. ZBX-26986

Secondary-order SQL injection in Zabbix Server when deleting an autoregistered host (CVE-2025-27240)

XMLWordPrintable

    • Icon: Defect (Security) Defect (Security)
    • Resolution: Fixed
    • Icon: Major Major
    • None
    • None
    • Server (S)
    • None

      CVE ID CVE-2025-27240
      CVSS score 7.5 (High)
      CVSS vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
      Affected components Server
      Summary Secondary-order SQL injection in Zabbix Server when deleting an autoregistered host
      Description A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.
      Known attack vectors The attacker needs to be a Zabbix administrator and also needs access to a host that is later auto-removed.
      Affected and fix version/s Affected: 6.0.0 - 6.0.33 → Fixed: 6.0.34
      Affected: 6.4.0 - 6.4.18 → Fixed: 6.0.19
      Affected: 7.0.0 - 7.0.3 → Fixed: 7.0.4
      Mitigation Update the affected components to their respective fixed versions.
      Workarounds Disable any Autoregistration actions that remove hosts.
      Acknowledgements Zabbix wants to thank Grzegorz Muszyński (szerszen199) for submitting this report on the HackerOne bug bounty platform.

            zabbix.support Zabbix Support Team
            jnulle Janis Nulle
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: