CVE-2026-23927
Zabbix Server vulnerability analysis and mitigation

Overview

CVE-2026-23927 is a TNS connection string injection vulnerability in Zabbix Agent 2's Oracle plugin that allows a high-privileged user with network access to inject a malicious Oracle TNS connection string via the service parameter. This can cause Agent 2 to connect to an attacker-controlled server and leak Oracle database credentials stored in named sessions. Affected versions include Zabbix 6.0.0–6.0.44, 7.0.0–7.0.23, and 7.4.0–7.4.7. It was published on May 6, 2026, and carries a CVSS v4.0 base score of 5.1 (Medium) (Zabbix Advisory, GitHub Advisory).

Technical details

The vulnerability is rooted in insufficient input validation of the service parameter in Zabbix Agent 2's Oracle monitoring plugin, classified under CWE-522 (Insufficiently Protected Credentials) and CWE-88 (Improper Neutralization of Argument Delimiters in a Command — Argument Injection). An attacker who can send requests to Agent 2 can craft a malicious Oracle TNS connection string that redirects the agent's database connection to an attacker-controlled server. Exploitation requires the attacker to hold high privileges and for Oracle database credentials to be stored in a named session configuration; the attack vector is network-based with no user interaction required (Zabbix Advisory, GitHub Advisory).

Impact

Successful exploitation results in the exfiltration of Oracle database credentials stored in Zabbix named sessions, representing a high confidentiality impact on subsequent systems. The integrity of the vulnerable system itself is also marginally affected (Low integrity impact). Because the leaked credentials are for Oracle databases, an attacker could use them for unauthorized database access, lateral movement within the database environment, or further data exfiltration (Zabbix Advisory, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify Zabbix Agent 2 instances monitoring Oracle databases, particularly those using named sessions with stored credentials. Confirm the affected version range (6.0.0–6.0.44, 7.0.0–7.0.23, or 7.4.0–7.4.7).
  2. Obtain high-privileged access: Acquire credentials or a session with sufficient privileges to send requests to the Zabbix Agent 2 Oracle plugin (e.g., via a compromised Zabbix server or administrative account).
  3. Craft malicious TNS string: Construct a malicious Oracle TNS connection string in the service parameter that redirects the connection to an attacker-controlled server (e.g., by specifying a custom HOST and PORT in the TNS descriptor).
  4. Set up rogue Oracle listener: Stand up a fake Oracle TNS listener on the attacker-controlled server to capture incoming connection attempts and harvest any credentials transmitted during the handshake.
  5. Trigger the injection: Send the crafted request to Agent 2 with the malicious service parameter value, causing Agent 2 to initiate a connection to the attacker's server.
  6. Capture credentials: Collect the Oracle database credentials (username/password) transmitted by Agent 2 from the named session configuration (Zabbix Advisory).

Indicators of compromise

  • Network: Outbound connections from the Zabbix Agent 2 host to unexpected or external IP addresses on Oracle TNS ports (default TCP 1521); DNS queries or TCP connections to unfamiliar hostnames from the agent host.
  • Logs: Zabbix Agent 2 logs showing Oracle plugin connection attempts to non-standard or external hosts; connection errors or timeouts to unexpected Oracle endpoints in agent log files.
  • Configuration: Presence of named sessions in Zabbix Agent 2 configuration with Oracle credentials; unexpected modifications to the service parameter values in monitoring item configurations.
  • Process: Unusual network activity initiated by the Zabbix Agent 2 process (zabbix_agent2) to external or non-production database servers (Zabbix Advisory).

Mitigation and workarounds

Zabbix has released fixed versions addressing this vulnerability: 6.0.45, 7.0.24, and 7.4.8. Organizations should upgrade Agent 2 to the respective fixed version as the primary remediation (Zabbix Advisory). As a workaround, avoid using named sessions for Oracle database monitoring in Zabbix Agent 2, which prevents credentials from being stored and subsequently leaked. Additionally, restrict network access to Agent 2 to authorized users and systems only, and implement network segmentation to prevent Agent 2 from connecting to unexpected external servers.

Community reactions

The vulnerability was reported through Zabbix's HackerOne bug bounty program by researcher "kelsier" from clocktwice.com, and Zabbix acknowledged the report and issued fixes promptly (Zabbix Advisory). Red Hat tracked the issue via Bugzilla (Bug 2466967) as it affects Zabbix packages in their ecosystem (Red Hat Bugzilla). Community coverage has been limited to standard vulnerability aggregation sites and newsletters, with no significant broader security community debate noted.

Additional resources


SourceThis report was generated using AI

Related Zabbix Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23928HIGH7.3
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoNoMay 06, 2026
CVE-2026-23926HIGH7.3
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoNoMay 06, 2026
CVE-2026-23923MEDIUM6.9
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoNoMar 24, 2026
CVE-2026-23924MEDIUM6.1
  • Zabbix Server logoZabbix Server
  • zabbix
NoNoMar 24, 2026
CVE-2026-23927MEDIUM5.1
  • Zabbix Server logoZabbix Server
  • zabbix
NoNoMay 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management