{"id":"CVE-2026-23927","title":"A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter","summary":"A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-522"],"vendor":"zabbix","product":"zabbix","affected":["zabbix >= 6.0.0, < 6.0.45","zabbix >= 7.0.0, < 7.0.24","zabbix >= 7.4.0, < 7.4.8"],"patched":["zabbix 7.4.8"],"published":"2026-05-06","updated":"2026-09-18","sourceUpdated":"2026-09-18T15:26:56.730","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-23927","references":[{"url":"https://support.zabbix.com/browse/ZBX-27759","label":"security@zabbix.com"}],"tags":["nvd"],"epss":0.00222,"epssPercentile":0.13067,"ingestedAt":"2026-09-18T15:44:31.551Z","slug":"CVE-2026-23927","body":"## Overview\n\nA user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a named session.\n\n## Affected\n\n- `zabbix >= 6.0.0, < 6.0.45`\n- `zabbix >= 7.0.0, < 7.0.24`\n- `zabbix >= 7.4.0, < 7.4.8`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `zabbix 7.4.8`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}