Back

HIGH

Secondary-order SQL injection in Zabbix Server when deleting an autoregistered host

Published Sep 12, 2025

Description

A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.

Affected products

Remediation

Vendor solution

Update the affected components to their respective fixed versions.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Zabbix
Published Sep 12, 2025
Updated Feb 26, 2026
Reserved Feb 20, 2025
CISA Vulnrichment
Updated Sep 13, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a