CVE Database
/

CVE-2026-23927

Back to search

CVE-2026-23927

Published: May 6, 2026

Modified: May 6, 2026

PUBLISHED

Description

A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a named session.

VendorProductVersions

Zabbix

Zabbix

affected
6.0.0 - <= 6.0.44
affected
7.0.0 - <= 7.0.23
affected
7.4.0 - <= 7.4.7

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now