CVE-2026-23921Disclosure(zabbix / zabbix)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch zabbix zabbix systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based techniques, potentially leading to session identifier disclosure and administrator account compromise.

4.3/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zabbix

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 14 mentions across 8 observed days
  • Momentum state: rising

What's happening

  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 13 signals
  • Disclosure: 7 classified signals
  • Peaked 1d ago at 3 mentions (2026-09-23); latest day: 3
  • 14 total mentions across 8 days

Affected systems

Vendors
Products
zabbix

Deep dive

Activity timeline14 mentions / 8d
01223Mentions · 2026-03-26: 1Mentions · 2026-03-27: 2Mentions · 2026-03-28: 1Mentions · 2026-03-30: 1Mentions · 2026-03-31: 1Mentions · 2026-04-01: 2Mentions · 2026-09-23: 3Mentions · 2026-09-24: 3PoC Mentioned / Linked · 2026-09-23: 3PoC Mentioned / Linked · 2026-09-24: 2Exploit Tool / Code · 2026-09-23: 3Exploit Tool / Code · 2026-09-24: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-09-23: 2Patch / Workaround · 2026-09-24: 2Technical Details · 2026-03-26: 1Technical Details · 2026-03-27: 2Technical Details · 2026-03-28: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-01: 2Technical Details · 2026-09-23: 3Technical Details · 2026-09-24: 303-2603-2703-2803-3003-3104-0109-2309-24
Signal classification4 categories
Disclosure
750.0%
PoC
321.4%
Patch
214.3%
Exploit
214.3%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-261
Patch1
2026-03-272
Disclosure2
2026-03-281
Disclosure1
2026-03-301
Disclosure1
2026-03-311
Disclosure1
2026-04-012
Disclosure2
2026-09-233
Exploit2PoC1
2026-09-243
Patch1PoC2
Full discourse14 posts
  • yousukezan@yousukezan
    Disclosure

    【緊急】Zabbix の脆弱性情報 CVE-2026-23921 (CVSS 8.7) https://blog.usize-tech.com/zabbix-vulnerability-cve-2026-23921/

    Post summary

    An emergency notice announces the Zabbix vulnerability CVE-2026-23921, indicating its CVSS score of 8.7 and linking to a blog post for more information.

    07152759143.9K
    14.3K followersView on X
  • ThreatWire@ThreatWire_
    Exploit

    🚨 PoC RELEASED: A public exploit is now available for CVE-2026-23921, a HIGH-severity SQL injection in Zabbix (CVSS 8.7). A low-privileged Zabbix user with API access can exploit the sortfield parameter to perform blind SQL injection and exfiltrate database information through time-based techniques. ⚠️ The flaw can potentially expose session identifiers and lead to administrator account compromise. 🔴 Fixed in Zabbix 7.0.22, 7.2.15 and 7.4.6. Update affected installations. 🔗 https://github.com/qucklecrabik/cve-2026-23921 #Zabbix #CVE #SQLi #PoC #CyberSecurity #Infosec

    Post summary

    A public exploit for CVE-2026-23921 (SQL injection in Zabbix, CVSS 8.7) has been released via a GitHub repository; patches are available in Zabbix 7.0.22, 7.2.15, and 7.4.6.

    011037162.5K
    1.7K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 Zabbix'teki CVE-2026-23921 güvenlik açığı için PoC exploit yayınlandı. Açık, kimlik doğrulaması gerektiren Zabbix API servislerinde groupBy ve sortfield parametrelerinin işlenmesi üzerinden time-based blind SQL injection yapılmasına olanak sağlıyor. Etkilenen sürümler: • 7.0 < 7.0.22 • 7.2 < 7.2.15 • 7.4 < 7.4.6 Güncel sürümler: 7.0.22 / 7.2.15 / 7.4.6+ https://github.com/qucklecrabik/cve-2026-23921

    Post summary

    A PoC exploit for CVE-2026-23921 has been published, detailing a time-based blind SQL injection in Zabbix API services, with affected versions and fixed releases (7.0.22, 7.2.15, 7.4.6+) along with a GitHub reference.

    020106647
    2.4K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Zabbix patches a high-severity blind SQL injection (CVE-2026-23921) in its API. Attackers can hijack sessions and steal data. Update to 7.4.6 or later today! #Zabbix #CyberSecurity #SQLInjection #InfoSec #Vulnerability #PatchAlert #Monitoring #API #CVE https://securityonline.info/zabbix-api-sql-injection-vulnerability-cve-2026-23921/ https://t.co/pTZYGcYO71

    Post summary

    The tweet announces a patch for CVE-2026-23921, a high‑severity blind SQL injection in Zabbix's API, urging users to upgrade to version 7.4.6 or newer to prevent session hijacking and data theft.

    14033386
    10.9K followersView on X
  • tatematsu_san@tk4_jj
    Disclosure

    ふむ 【緊急】Zabbix の脆弱性情報 CVE-2026-23921 (CVSS 8.7) – TechHarmony https://share.google/O9VvJAzk4jyAdACkA

    Post summary

    An urgent alert has been posted by TechHarmony about a CVE-2026-23921 vulnerability in Zabbix, with a CVSS score of 8.7, but no PoC, exploit, or patch details are included.

    01040393
    2.5K followersView on X
  • dbugs@ptdbugs
    Exploit

    A PoC/exploit has been discovered for vulnerability CVE-2026-23921 PT ID: PT-2026-27475 Vendor: Zabbix Product: Zabbix Description: A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based techniques, potentially leading to session identifier disclosure and administrator account compromise. References: • https://dbu.gs/vulnerability/PT-2026-27475 • https://github.com/qucklecrabik/cve-2026-23921

    Post summary

    The text announces the discovery of a PoC/exploit for a blind SQL injection vulnerability in Zabbix (CVE-2026-23921) and provides a link to a GitHub repository containing the exploit code, while detailing technical aspects of the vulnerability.

    00021510
    3.6K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Zabbix ❗ CVE-2026-23921 ❗ CVE-2026-23920 ❗ CVE-2026-23919 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-zabbix/ https://t.co/qiJNKLih5o

    Post summary

    The post lists three CVE vulnerabilities in Zabbix products and directs readers to a CERT page for more information, but does not provide proof‑of‑concepts, exploit code, patches, or evidence of active exploitation.

    10020179
    6.6K followersView on X
  • Misbar | مسبار@MisbarSec
    Disclosure

    📌 ثغرة Zabbix API: حقن SQL عالي الخطورة يهدد أمن مراقبة الشبكات تم الكشف عن ثغرة أمنية حرجة من نوع SQL injection (CVE-2026-23921) ضمن واجهة برمجة تطبيقات Zabbix API، مما يهدد أنظمة المراقبة الشبكية. تستهدف هذه الثغرة، المصنفة كعالية الخطورة، قدرة الحلول مفتوحة المصدر على تتبع حالة الخدمات والخوادم، معرضة البيانات الحساسة للخطر. يتيح الاستغلال الناجح للثغرة للمهاجمين تنفيذ أوامر SQL عشوائية، مما قد يؤدي إلى الوصول غير المصرح به لقواعد البيانات والتلاعب بالمعلومات أو تعطيل الأنظمة. يُنصح بضرورة إجراء تحديثات فورية لجميع أنظمة Zabbix المتأثرة للحد من مخاطر الاستغلال المحتمل. 🔗 للمزيد: https://securityonline.info/zabbix-api-sql-injection-vulnerability-cve-2026-23921/ #الامن_السيبراني #cybersecurity #cve

    Post summary

    A high‑severity SQL injection vulnerability (CVE‑2026‑23921) was disclosed in the Zabbix API, urging users to apply patches immediately. No PoC, exploit code, or evidence of active exploitation is mentioned.

    0003097
    96 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    🚨 PoC RELEASED | Zabbix SQL Injection A public PoC is now available for CVE-2026-23921, a CVSS 8.7 High SQL injection affecting Zabbix. 💥 Type: Time-based blind SQLi 🔐 Auth: Low-privileged API user 🎯 Impact: Database information exposure, potentially including session data

    Post summary

    A public Proof of Concept has been released for CVE-2026-23921, a high‑severity SQL injection in Zabbix that can be exploited by low‑privileged API users via time‑based blind SQLi to expose database information and potentially session data.

    1001069
    307 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『potentially leading to session identifier disclosure and administrator account compromise.』 [ZBX-27640] Blind, read-only SQL injection in Zabbix API via sortfield parameter (CVE-2026-23921) - ZABBIX SUPPORT https://support.zabbix.com/browse/ZBX-27640

    Post summary

    The Zabbix support page discloses a blind, read‑only SQL injection vulnerability (CVE‑2026‑23921) that could lead to session ID exposure and admin account compromise, but it provides no PoC, exploit, patch, or evidence of active exploitation.

    00010388
    6.8K followersView on X
  • VulnTracker@vuln_tracker
    Patch

    A low-privileged Zabbix user can blindly extract your entire database (CVSS 8.8). CVE-2026-23921 is a blind SQL injection in the sortfield parameter of Zabbix's API. Results aren't returned directly, but time-based techniques let an attacker exfiltrate data, up to and including session IDs and admin credentials. Affects Zabbix 7.0.0 through 7.0.21, plus 7.2.0 and 7.4.0. Fixed in 7.0.22. Details: http://vulntracker.io/cves/CVE-2026-23921 Follow for the critical CVEs that matter, every day. #Zabbix #CVE #InfoSec #CyberSecurity

    Post summary

    The tweet discloses CVE-2026-23921, a blind SQL injection in Zabbix API, but the primary actionable information is the specific fixed version (7.0.22), making it a Patch classification despite the technical disclosure.

    00000160
    783 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    ✅ Fixed: Zabbix 7.0.22, 7.2.15 &amp; 7.4.6+ 🔗 CVE: CVE-2026-23921 🔗 PoC: GitHub PoC ⚠️ Update affected installations. #Zabbix #CVE #SQLi #CyberSecurity #InfoSe

    Post summary

    Tweet discloses CVE-2026-23921 (Zabbix SQLi) with fixed versions 7.0.22/7.2.15/7.4.6+, links a GitHub PoC, and urges updates; PoC classification applies as the main takeaway is the PoC availability rather than a functional exploit or just a patch.

    0000047
    307 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    Zabbix APIにブラインドSQLインジェクションが可能になる脆弱性(CVE-2026-23921) https://rocket-boys.co.jp/security-measures-lab/zabbix-api-blind-sql-injection-cve-2026-23921/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The post announces a blind SQL injection vulnerability (CVE-2026-23921) affecting the Zabbix API, providing a technical description but no PoC, exploit, patch, or evidence of exploitation.

    00000156
    363 followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    Disclosure

    Zabbix API Vulnerability: High-Severity SQL Injection Threatens Network Monitoring Security https://securityonline.info/zabbix-api-sql-injection-vulnerability-cve-2026-23921/

    Post summary

    The text announces a high‑severity SQL injection vulnerability in the Zabbix API (CVE‑2026‑23921), but provides no evidence of PoC, exploit code, active exploitation, or patch details.

    00000214
    242 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appzabbixzabbix---

Explore more