A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.
Fixes

Solution

Update the affected components to their respective fixed versions.


Workaround

Disable any Autoregistration actions that remove hosts.

History

Fri, 12 Sep 2025 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 12 Sep 2025 10:45:00 +0000

Type Values Removed Values Added
Description A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.
Title Secondary-order SQL injection in Zabbix Server when deleting an autoregistered host
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zabbix

Published:

Updated: 2025-09-12T11:53:44.446Z

Reserved: 2025-02-20T11:40:38.480Z

Link: CVE-2025-27240

cve-icon Vulnrichment

Updated: 2025-09-12T11:53:38.647Z

cve-icon NVD

Status : Received

Published: 2025-09-12T11:15:31.633

Modified: 2025-09-12T11:15:31.633

Link: CVE-2025-27240

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.