
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23927 is a TNS connection string injection vulnerability in Zabbix Agent 2's Oracle plugin that allows a high-privileged user with network access to inject a malicious Oracle TNS connection string via the service parameter. This can cause Agent 2 to connect to an attacker-controlled server and leak Oracle database credentials stored in named sessions. Affected versions include Zabbix 6.0.0–6.0.44, 7.0.0–7.0.23, and 7.4.0–7.4.7. It was published on May 6, 2026, and carries a CVSS v4.0 base score of 5.1 (Medium) (Zabbix Advisory, GitHub Advisory).
The vulnerability is rooted in insufficient input validation of the service parameter in Zabbix Agent 2's Oracle monitoring plugin, classified under CWE-522 (Insufficiently Protected Credentials) and CWE-88 (Improper Neutralization of Argument Delimiters in a Command — Argument Injection). An attacker who can send requests to Agent 2 can craft a malicious Oracle TNS connection string that redirects the agent's database connection to an attacker-controlled server. Exploitation requires the attacker to hold high privileges and for Oracle database credentials to be stored in a named session configuration; the attack vector is network-based with no user interaction required (Zabbix Advisory, GitHub Advisory).
Successful exploitation results in the exfiltration of Oracle database credentials stored in Zabbix named sessions, representing a high confidentiality impact on subsequent systems. The integrity of the vulnerable system itself is also marginally affected (Low integrity impact). Because the leaked credentials are for Oracle databases, an attacker could use them for unauthorized database access, lateral movement within the database environment, or further data exfiltration (Zabbix Advisory, GitHub Advisory).
service parameter that redirects the connection to an attacker-controlled server (e.g., by specifying a custom HOST and PORT in the TNS descriptor).service parameter value, causing Agent 2 to initiate a connection to the attacker's server.service parameter values in monitoring item configurations.zabbix_agent2) to external or non-production database servers (Zabbix Advisory).Zabbix has released fixed versions addressing this vulnerability: 6.0.45, 7.0.24, and 7.4.8. Organizations should upgrade Agent 2 to the respective fixed version as the primary remediation (Zabbix Advisory). As a workaround, avoid using named sessions for Oracle database monitoring in Zabbix Agent 2, which prevents credentials from being stored and subsequently leaked. Additionally, restrict network access to Agent 2 to authorized users and systems only, and implement network segmentation to prevent Agent 2 from connecting to unexpected external servers.
The vulnerability was reported through Zabbix's HackerOne bug bounty program by researcher "kelsier" from clocktwice.com, and Zabbix acknowledged the report and issued fixes promptly (Zabbix Advisory). Red Hat tracked the issue via Bugzilla (Bug 2466967) as it affects Zabbix packages in their ecosystem (Red Hat Bugzilla). Community coverage has been limited to standard vulnerability aggregation sites and newsletters, with no significant broader security community debate noted.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."