ZABBIX SUPPORT

Defect (Security)
Minor
Created descending
15 of 32 as at: 2026 Jun 02 19:47
T Key Summary Assignee Reporter P Status Resolution Created Updated Due Development
Defect (Security) ZBX-27759

Agent 2 Oracle plugin TNS connection string injection via the 'service' parameter (CVE-2026-23927)

Zabbix Support Team Janis Nulle Minor Closed Fixed  
Defect (Security) ZBX-27284

Frontend DoS vulnerability due to asymmetric resource consumption (CVE-2025-49643)

Zabbix Support Team Janis Nulle Minor Closed Fixed  
Defect (Security) ZBX-27283

Agent builds for AIX vulnerable to library loading hijacking (CVE-2025-49642)

Zabbix Support Team Janis Nulle Minor Closed Fixed  
Defect (Security) ZBX-27282

Frontend arbitrary file read in oauth.authorize action (CVE-2025-27232)

Zabbix Support Team Janis Nulle Minor Closed Fixed  
Defect (Security) ZBX-27060

User information disclosure via api_jsonrpc.php on method user.get with param search (CVE-2025-27236)

Zabbix Support Team Janis Nulle Minor Closed Fixed