No analysis available yet.
Vendor Solution
Update the affected components to their respective fixed versions.
Vendor Workaround
Disable any Autoregistration actions that remove hosts.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29033 | A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field. |
| Link | Providers |
|---|---|
| https://support.zabbix.com/browse/ZBX-26986 |
|
Wed, 08 Oct 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Mon, 15 Sep 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zabbix
Zabbix zabbix |
|
| Vendors & Products |
Zabbix
Zabbix zabbix |
Fri, 12 Sep 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Sep 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field. | |
| Title | Secondary-order SQL injection in Zabbix Server when deleting an autoregistered host | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Zabbix
Published:
Updated: 2026-02-26T17:48:38.935Z
Reserved: 2025-02-20T11:40:38.480Z
Link: CVE-2025-27240
Updated: 2025-09-12T11:53:38.647Z
Status : Analyzed
Published: 2025-09-12T11:15:31.633
Modified: 2025-10-08T14:53:38.077
Link: CVE-2025-27240
No data.
OpenCVE Enrichment
Updated: 2025-09-15T10:43:58Z
EUVD