Zabbix Blind SQL Injection Vulnerability in API Sortfield Parameter

Vulnerability

A blind SQL injection vulnerability has been identified in the Zabbix API, specifically in versions 7.0.0 through 7.0.21, 7.2.0 through 7.2.14, and 7.4.0 through 7.4.5. This vulnerability allows a low-privilege user with API access to execute arbitrary SQL select statements via the sortfield parameter. Although the results of these queries are not returned directly, an attacker can use time-based techniques to exfiltrate database information. This could potentially lead to the disclosure of session identifiers and compromise of administrator accounts.

Impact

Exploitation of this vulnerability could result in unauthorized access to database information, including session identifiers, which could be used to compromise administrator accounts.

Remediation

Users can update to Zabbix versions 7.0.22, 7.2.15, or 7.4.6 to address this vulnerability.

Added: Mar 24, 2026, 7:43 PM
Updated: Mar 24, 2026, 7:43 PM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
5.0
exploitability
5.2
remediation
7.7
relevance
4.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.