A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a named session.
{
"cpe": "cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "6.0.0"
},
{
"fixed": "6.0.45"
},
{
"introduced": "7.0.0"
},
{
"fixed": "7.0.24"
},
{
"introduced": "7.4.0"
},
{
"fixed": "7.4.8"
}
],
"source": "CPE_RANGE"
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23927.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"2575989339259640105311353590351376328",
"261745388088049729003388450910874131284",
"78615119555629258408370069502963169562",
"106265636532305374733445754623506502550",
"142981670864924541529460717571059194747",
"276456720699755867738555225603931221904"
],
"threshold": 0.9
},
"id": "CVE-2026-23927-3c3866b9",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zabbix/zabbix/commit/6b0f6b25da00d2c2a0dc2035ba2285aa51c85865",
"target": {
"file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"13006993947316681917700725759978790726",
"246202365619345375288485124626876863591",
"211408096376471392416611541472284431260",
"270294714855371664368322160720009475489",
"60583027902879434151887895598095070927",
"190443916206833154001079149101507226106"
],
"threshold": 0.9
},
"id": "CVE-2026-23927-84ec59d2",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zabbix/zabbix/commit/d8c5768f7d09e99586d81237c2c891ce20280cc8",
"target": {
"file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"328694341909655700810807882163230140941",
"12061819213497335241319149757757382988",
"8781501731097225876935453466613140553",
"132482256639643116861018651525990961205",
"188121564415475832297632590253969155136",
"36080719019429417973525356404344529663"
],
"threshold": 0.9
},
"id": "CVE-2026-23927-92c6c503",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zabbix/zabbix/commit/36bdd34b378e8731c7c825df38c364e00a76e6a5",
"target": {
"file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
}
}
]
"2026-09-20T14:24:11Z"