A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-29033 A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.
Fixes

Solution

Update the affected components to their respective fixed versions.


Workaround

Disable any Autoregistration actions that remove hosts.

History

Wed, 08 Oct 2025 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Mon, 15 Sep 2025 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Zabbix
Zabbix zabbix
Vendors & Products Zabbix
Zabbix zabbix

Fri, 12 Sep 2025 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 12 Sep 2025 10:45:00 +0000

Type Values Removed Values Added
Description A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.
Title Secondary-order SQL injection in Zabbix Server when deleting an autoregistered host
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zabbix

Published:

Updated: 2025-09-15T12:49:03.144Z

Reserved: 2025-02-20T11:40:38.480Z

Link: CVE-2025-27240

cve-icon Vulnrichment

Updated: 2025-09-12T11:53:38.647Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-12T11:15:31.633

Modified: 2025-10-08T14:53:38.077

Link: CVE-2025-27240

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-15T10:43:58Z