Skip to content

CVE lookup

CVE-2026-23921

Pruva has a verified reproduction for CVE-2026-23921: Blind SQL injection in Zabbix API `CApiService.php` via the `sortfield` parameter allows low-privileged API users to exfiltrate database data and potentially compromise administrator accounts.. The canonical evidence record is REPRO-2026-00360.

REPRO

REPRO-2026-00360

Package

zabbix/zabbix · unknown

Severity

HIGH

Status

published