#VU124618 SQL Injection: Hibernate in Zabbix - CVE-2026-23921
Published: March 25, 2026
Zabbix
Zabbix
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to blind SQL injection in the Zabbix API via the sortfield parameter in include/classes/api/CApiService.php when processing API requests. A remote user can send a specially crafted API request to exfiltrate arbitrary database data through time-based techniques, potentially leading to session identifier disclosure and administrator account compromise.
Access to a Zabbix account with API access is required to exploit this vulnerability.