
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-27240 is a secondary-order SQL injection vulnerability in Zabbix Server that allows an authenticated administrator to inject arbitrary SQL commands during the auto-removal of hosts by inserting malicious SQL in the 'Visible name' field. It was disclosed on September 12, 2025, and affects Zabbix versions 6.0.0–6.0.33, 6.4.0–6.4.18, and 7.0.0–7.0.3. The vulnerability carries a CVSS v3.1 base score of 7.2 (High) and a CVSS v4.0 base score of 7.5 (High) (Zabbix Advisory, Red Hat).
The root cause is improper neutralization of special elements used in an SQL command (CWE-89), specifically a secondary-order (stored) SQL injection. An attacker with Zabbix administrator privileges sets a malicious SQL payload in the 'Visible name' field of a host; this stored value is later unsafely incorporated into a SQL query when the Zabbix Server's autoregistration action triggers host deletion/removal. Exploitation requires the attacker to have administrator-level access and for an autoregistration action that removes hosts to be configured and triggered (Zabbix Advisory).
Successful exploitation could allow an authenticated administrator to execute arbitrary SQL commands against the Zabbix database, leading to unauthorized data access, data manipulation, and potential full database compromise. This threatens the confidentiality, integrity, and availability of the Zabbix monitoring system and any sensitive infrastructure data it stores, such as host credentials, monitoring configurations, and network topology (Zabbix Advisory, Red Hat).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.039%, reflecting a low probability of near-term exploitation. Exploitation requires high privileges (Zabbix administrator access) and a specific configuration (autoregistration actions that remove hosts must be enabled), significantly limiting the attack surface (Zabbix Advisory, Feedly).
hosts, users, config) not attributable to normal administrative activity; new or modified records inconsistent with known administrator actions.--, /**/, UNION, SELECT) that are not part of legitimate naming conventions.xp_cmdshell on MSSQL or LOAD_FILE/INTO OUTFILE on MySQL).Zabbix has released patched versions addressing this vulnerability: 6.0.34 (for 6.0.x), 6.4.19 (for 6.4.x), and 7.0.4 (for 7.0.x). Organizations unable to upgrade immediately should disable any autoregistration actions configured to remove hosts as a temporary workaround. Additionally, restricting administrator access following the principle of least privilege and auditing administrator actions are recommended compensating controls (Zabbix Advisory).
The vulnerability was reported to Zabbix via the HackerOne bug bounty platform by researcher Grzegorz Muszyński (szerszen199), and Zabbix acknowledged the submission. Red Hat has also tracked the CVE for its products. No significant broader media coverage or notable community debate has been observed beyond standard vulnerability database entries (Zabbix Advisory, Red Hat).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."