Zabbix
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Zabbix product.
RSS Feeds for Zabbix security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Zabbix products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Zabbix Sorted by Most Security Vulnerabilities since 2018
Known Exploited Zabbix Vulnerabilities
The following Zabbix vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Zabbix Frontend Authentication Bypass Vulnerability |
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML. CVE-2022-23131 Exploit Probability: 95.7% |
February 22, 2022 |
| Zabbix Frontend Improper Access Control Vulnerability |
Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend. CVE-2022-23134 Exploit Probability: 84.7% |
February 22, 2022 |
Of the known exploited vulnerabilities above, 2 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 20 vulnerabilities in Zabbix with an average score of 5.6 out of ten. Last year, in 2025 Zabbix had 16 security vulnerabilities published. That is, 4 more vulnerabilities have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 20 | 5.56 |
| 2025 | 16 | 0.00 |
| 2024 | 17 | 5.55 |
| 2023 | 19 | 7.19 |
| 2022 | 15 | 5.32 |
| 2021 | 1 | 8.80 |
| 2020 | 2 | 6.10 |
| 2019 | 3 | 0.00 |
It may take a day or so for new Zabbix vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Zabbix Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-59781 | Aug 18, 2026 |
When Zabbix Agent was installed on Windows into a custom installation directoryWhen Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether the selected directory had secure access permissions. If the target directory allowed unauthorized users to modify its contents, an attacker could place a malicious DLL that could later be loaded by the application, resulting in DLL sideloading. The installer has been hardened to detect potentially unsafe installation directories and now requires explicit user confirmation before proceeding with installation in such locations. This reduces the risk of accidental installation into directories with inappropriate permissions while preserving compatibility with existing deployment scenarios. |
|
| CVE-2026-23938 | Aug 18, 2026 |
An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scriptsAn authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service. |
|
| CVE-2026-23937 | Aug 18, 2026 |
The Zabbix API host.get actionThe Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity. |
|
| CVE-2026-23935 | Aug 18, 2026 |
A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logicA Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss. |
|
| CVE-2026-23934 | Aug 18, 2026 |
An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists actionAn authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading to potential denial of service. |
|
| CVE-2026-23933 | Aug 18, 2026 |
In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seedIn Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that utilize both - SAML authentication and guest users. In such cases the key can be used to forge valid session cookies, potentially leading to unauthorized access. For other Zabbix deployments this does not have a known impact. |
|
| CVE-2026-23931 | Aug 18, 2026 |
The frontend validatate.api.exists actionThe frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality. |
|
| CVE-2026-23930 | Aug 18, 2026 |
An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr actionAn unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service. |
|
| CVE-2026-23929 | Aug 18, 2026 |
Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in MapsPrototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation that traversed the prototype chain. |
|
| CVE-2026-1199 | Aug 18, 2026 |
Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent simultaneously, potentiallyZabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent simultaneously, potentially allowing for more password guesses than intended. |
|
| CVE-2026-23922 | Aug 18, 2026 |
The email media OAuth field 'Client secret'The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint. |
|
| CVE-2026-23928 | May 06, 2026 |
Zabbix 6.0/7.0+ XSS via Item History or Plain Text Widget with HTML DisplayThe Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0. |
|
| CVE-2026-23927 | May 06, 2026 |
Zabbix Agent 2 Oracle TNS Injection via Service ParameterA user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a named session. |
|
| CVE-2026-23926 | May 06, 2026 |
Zabbix Frontend Authenticated XSS via Maintenance TooltipAn authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip. |
|
| CVE-2026-23924 | Mar 24, 2026 |
Zabbix Agent 2 Docker Plugin Improper Sanitization Enables Arbitrary File ReadZabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting them via the Docker archive API. |
|
| CVE-2026-23923 | Mar 24, 2026 |
Zabbix Frontend Arbitrary Class Instantiation via 'validate' ActionAn unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time. |
|
| CVE-2026-23921 | Mar 24, 2026 |
Zabbix API blind SQLi via sortfield in CApiService.phpA low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based techniques, potentially leading to session identifier disclosure and administrator account compromise. |
|
| CVE-2026-23920 | Mar 24, 2026 |
Zabbix Script Regex Injection via Multiline ModeHost and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands. |
|
| CVE-2026-23919 | Mar 24, 2026 |
Zabbix 7.4 Duktape Context Reuse Exposes DataFor performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A fix has been released that makes the built in Zabbix JavaScript objects read-only, but please be advised that usage of global JavaScript variables is not recommended because their content could be leaked. More information <a href='https://www.zabbix.com/documentation/7.4/en/manual/installation/known_issues#preprocessing-global-variables-are-unsafe'>in Zabbix documentation</a>. |
|
| CVE-2026-23925 | Mar 06, 2026 |
Zabbix Authenticated API import privilege escalationAn authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions. |
|
| CVE-2025-49643 | Dec 01, 2025 |
Zabbix Auth User Can Trigger CPU DoS via imgstore.phpAn authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service. |
|
| CVE-2025-49642 | Dec 01, 2025 |
Local User Hijack of Zabbix Agent Library Loading on AIXLibrary loading on AIX Zabbix Agent builds can be hijacked by local users with write access to the /home/cecuser directory. |
|
| CVE-2025-27232 | Dec 01, 2025 |
Zabbix AuthSupAdmin OAuth Auth Reads Files (CVE-2025-27232)An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss. |
|
| CVE-2025-49641 | Oct 03, 2025 |
Zabbix: Unprivileged User Can Retrieve Active Problem ListA regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refresh action and therefore still retrieve a list of active problems. |
|
| CVE-2025-27237 | Oct 03, 2025 |
Zabbix Agent/2 LPE via Writable OpenSSL Config on WindowsIn Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded from a path writable by low-privileged users, allowing malicious modification and potential local privilege escalation by injecting a DLL. |
|
| CVE-2025-27236 | Oct 03, 2025 |
Zabbix API DataMining via Unauthorized Select FieldsA regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to. |
|
| CVE-2025-27231 | Oct 03, 2025 |
Okta LDAP Bind PWD Leak via Host ChangeThe LDAP 'Bind password' value cannot be read after saving, but a Super Admin account can leak it by changing LDAP 'Host' to a rogue LDAP server. To mitigate this, the 'Bind password' value is now reset on 'Host' change. |
|
| CVE-2025-27240 | Sep 12, 2025 |
SQLi in Zabbix Host Autoremoval via Visible Name FieldA Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field. |
|
| CVE-2025-27238 | Sep 12, 2025 |
Zabbix API hostprototype.get Host Proto Leak to Unprivileged UsersDue to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them. |
|
| CVE-2025-27233 | Sep 12, 2025 |
Zabbix Agent 2 smtctl Plugin: Param Injection Leaks NTLMv2Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. This can be used to leak the NTLMv2 hash from a Windows system. |
|
| CVE-2025-27234 | Sep 12, 2025 |
Zabbix Agent 2 smartctl RCE via unsanitized smart.disk.get (<=5.0)Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this allows for remote code execution. |
|
| CVE-2024-45699 | Apr 02, 2025 |
Zabbix XSS in /zabbix.php?action=export.valuemaps via backurlThe endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload may be injected into the above endpoint causing it to be executed within the context of the victim's browser. |
|
| CVE-2024-36469 | Apr 02, 2025 |
Login Timing Attack: Different Response for Non-Existing UserExecution time for an unsuccessful login differs when using a non-existing username compared to using an existing one. |
|
| CVE-2024-42325 | Apr 02, 2025 |
Zabbix API user.get Exposes Sensitive User DataZabbix API user.get returns all users that share common group with the calling user. This includes media and other information, such as login attempts, etc. |
|
| CVE-2024-45700 | Apr 02, 2025 |
Uncontrolled Resource Exhaustion in Zabbix Server Enables DoSZabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will cause the server to allocate an excessive amount of memory and perform CPU-intensive decompression operations, ultimately leading to a service crash. |
|
| CVE-2024-36465 | Apr 02, 2025 |
Zabbix API SQLi via groupBy in CApiService.phpA low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter. |
|
| CVE-2024-36464 | Nov 27, 2024 |
Plaintext Password Export via YAML in Media TypesWhen exporting media types, the password is exported in the YAML in plain text. This appears to be a best practices type issue and may have no actual impact. The user would need to have permissions to access the media types and therefore would be expected to have access to these passwords. |
|
| CVE-2024-42327 | Nov 27, 2024 |
Zabbix PHP API SQLi in CUser::addRelatedObjects via get()A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function which is available for every user who has API access. |
|
| CVE-2024-42330 | Nov 27, 2024 |
HttpRequest Header Encoding Flaw Enables Prototype Pollution in Edge JSThe HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem is that the returned strings are created directly from the data returned by the server and are not correctly encoded for JavaScript. This allows to create internal strings that can be used to access hidden properties of objects. |
|
| CVE-2024-42333 | Nov 27, 2024 |
Zabbix Server Out-of-Bounds Read Memory Leak Vulnerability in Email ModuleThe researcher is showing that it is possible to leak a small amount of Zabbix Server memory using an out of bounds read in src/libs/zbxmedia/email.c |
|
| CVE-2024-42332 | Nov 27, 2024 |
Zabbix SNMP Trap Log Parsing VulnerabilityThe researcher is showing that due to the way the SNMP trap log is parsed, an attacker can craft an SNMP trap with additional lines of information and have forged data show in the Zabbix UI. This attack requires SNMP auth to be off and/or the attacker to know the community/auth details. The attack requires an SNMP item to be configured as text on the target host. |
|
| CVE-2024-42331 | Nov 27, 2024 |
Zabbix: Use-After-Free Vulnerability in Duktape JavaScript Engine IntegrationIn the src/libs/zbxembed/browser.c file, the es_browser_ctor method retrieves a heap pointer from the Duktape JavaScript engine. This heap pointer is subsequently utilized by the browser_push_error method in the src/libs/zbxembed/browser_error.c file. A use-after-free bug can occur at this stage if the wd->browser heap pointer is freed by garbage collection. |
|
| CVE-2024-36467 | Nov 27, 2024 |
Zabbix API Privilege Escalation Vulnerability in User ManagementAn authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is enough to be able to add themselves to any group (e.g.: Zabbix Administrators), except to groups that are disabled or having restricted GUI access. |
|
| CVE-2024-22114 | Aug 12, 2024 |
ServiceNow: Unprivileged Host Stats Disclosure via SysInfo WidgetUser with no permission to any of the Hosts can access and view host count & other statistics through System Information Widget in Global View Dashboard. |
|
| CVE-2024-22122 | Aug 12, 2024 |
Zabbix Server AT Command Injection via Unvalidated SMS NumberZabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem. |
|
| CVE-2024-22121 | Aug 12, 2024 |
Zabbix Agent: Non-Admin Feature TamperingA non-admin user can change or remove important features within the Zabbix Agent application, thus impacting the integrity and availability of the application. |
|
| CVE-2024-22123 | Aug 12, 2024 |
Zabbix Server SMS Media Misconfig Lets Log File Corrupt & Leak via AT CommandsSetting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file for Linux, it is possible to set another file, e.g. log file and zabbix_server will try to communicate with it as modem. As a result, log file will be broken with AT commands and small part for log file content will be leaked to UI. |
|
| CVE-2024-36460 | Aug 12, 2024 |
Frontend Audit Log Exposure of Plaintext Passwords in Unknown ApplicationThe front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text. |
|
| CVE-2024-36461 | Aug 12, 2024 |
Zabbix JS Engine Pointer Modification VulnerabilityWithin Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine. |
|
| CVE-2024-36462 | Aug 12, 2024 |
Uncontrolled Resource Consumption (DoS) CVE-2024-36462Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources, such as CPU, memory, or network bandwidth, without proper limitations or controls. This can cause a denial-of-service (DoS) attack or degrade the performance of the affected system. |
|