Input validation error in Zabbix - CVE-2026-23927
Published: May 6, 2026
Zabbix
Zabbix
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper input validation in the Agent 2 Oracle plugin when processing the 'service' parameter in TNS connection strings. A remote privileged user can send a specially crafted request to disclose sensitive information.
Exploitation can cause Agent 2 to connect to an attacker-controlled server and leak Oracle database credentials if they are saved in a named session.