Input validation error in Zabbix - CVE-2026-23927
Published: May 6, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper input validation in the Agent 2 Oracle plugin when processing the 'service' parameter in TNS connection strings. A remote privileged user can send a specially crafted request to disclose sensitive information.
Exploitation can cause Agent 2 to connect to an attacker-controlled server and leak Oracle database credentials if they are saved in a named session.
Affected software
Fedora
zabbix6.0
zabbix7.0
How to mitigate CVE-2026-23927
zabbix6.0 - update to 6.0.46-1.el8
zabbix7.0 - addressed in versions 7.0.26-1.el8, 7.0.26-1.el10_1, 7.0.26-1.el10_2, 7.0.26-1.el10_3