A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based techniques, potentially leading to session identifier disclosure and administrator account compromise.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "7.2.0"
},
{
"fixed": "7.2.15"
}
],
"source": "CPE_RANGE",
"vendor_product": "zabbix:zabbix"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23921.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"335575185657139336988338025089072345512",
"144097728509264372924349761206701036791",
"185724688006201679055704973376898360796",
"130162026250320242787979560813111933511",
"70354792077183199662061649065794713982",
"152321436213664381476643075846246568564"
],
"threshold": 0.9
},
"id": "CVE-2026-23921-6d3c1d38",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zabbix/zabbix/commit/626d2b8a4820a424efe8fd39df3b706468f1e5d4",
"target": {
"file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"335575185657139336988338025089072345512",
"144097728509264372924349761206701036791",
"265387215296323665047876836033014923187",
"72110328909359773811350994976134420490",
"245919019046659487345219626549275780890",
"41189996272314509887159037345751552815"
],
"threshold": 0.9
},
"id": "CVE-2026-23921-8066b192",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zabbix/zabbix/commit/ba52e2ee4ff8768c8450819a772886d79dcde0b4",
"target": {
"file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
}
}
]
"2026-09-12T08:14:50Z"