CVE-2024-22120Disclosure(zabbix / zabbix)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch zabbix zabbix systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zabbix

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-12); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
zabbix

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-12: 2Mentions · 2026-03-25: 1PoC Mentioned / Linked · 2026-02-12: 1PoC Mentioned / Linked · 2026-03-25: 1Exploit Tool / Code · 2026-02-12: 1Exploit Tool / Code · 2026-03-25: 1Patch / Workaround · 2026-02-12: 1Technical Details · 2026-02-12: 102-1203-25
Signal classification3 categories
Disclosure
133.3%
PoC
133.3%
Exploit
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-122
Disclosure1PoC1
2026-03-251
Exploit1
Full discourse3 posts
  • Mustafa Adam Gamaraldin Abdalla 🇸🇩♥️@wadgamaraldeen
    Exploit

    هذا من فضل الله سبحانه و تعالى♥️ Finally my report got rewarded💰🎉 # More details about the vulnerability: 1- Security advisory + Exploit code: https://support.zabbix.com/browse/ZBX-24505 2- Another exploit: https://github.com/W01fh4cker/CVE-2024-22120-RCE Dorks in the first comment (: #BugBountyTips #CyberSecurity https://t.co/6Gsm6bQP4d

    Post summary

    The user shares exploit code for CVE-2024-22120 and links to a Zabbix security advisory, indicating the availability of functional exploitation scripts without evidence of active attacks or patches.

    350134755.3K
    3.7K followersView on X
  • Mustafa Adam Gamaraldin Abdalla 🇸🇩♥️@wadgamaraldeen
    Disclosure

    بفضل الله سبحانه وتعالى♥️ Identified a time-based blind SQLi in Zabbix (CVE-2024-22120) allowing privilege escalation from low-priv user to admin via audit log injection Improper sanitization→ DB extraction → session forgery→ potential RCE Thread👇 #BugBounty #AppSec #Zabbix https://t.co/a6ZtORXuCI

    Post summary

    The tweet discloses a time‑based blind SQLi in Zabbix (CVE‑2024‑22120) that can lead to privilege escalation and potential remote code execution.

    33069242.9K
    3.6K followersView on X
  • Mustafa Adam Gamaraldin Abdalla 🇸🇩♥️@wadgamaraldeen
    PoC

    - Zabbix Security Advisory: https://support.zabbix.com/browse/ZBX-24505 - PoC Repository: https://github.com/W01fh4cker/CVE-2024-22120-RCE

    Post summary

    A public PoC for CVE-2024-22120 is available via GitHub, and the linked Zabbix advisory indicates a vendor patch exists.

    00014412
    3.6K followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
Appzabbixzabbix---
Appzabbixzabbix7.0.0--
Appzabbixzabbix7.0.0--
Appzabbixzabbix7.0.0--
Appzabbixzabbix7.0.0--
Appzabbixzabbix7.0.0--
Appzabbixzabbix7.0.0--
Appzabbixzabbix7.0.0--
Appzabbixzabbix7.0.0--
Appzabbixzabbix7.0.0--
Appzabbixzabbix7.0.0--

Explore more