CVE-2025-27240: Secondary-order SQL injection in Zabbix Server when deleting an autoregistered host
Published Sep 12, 2025
·Updated
A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.
Affected Software
4 affected components
Zabbix Zabbix server
Zabbix Zabbix>=6.0.0<6.0.34
Zabbix Zabbix>=6.4.0<6.4.19
Zabbix Zabbix>=7.0.0<7.0.4
Remediation
Information
Update the affected components to their respective fixed versions.
Event History
Sep 12, 2025
CVE Published
via MITRE·10:33 AM
Data Sourced
via MITRE·10:33 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-27240?
CVE-2025-27240 has a high severity rating due to the potential for SQL injection, which can compromise the database.
2
How do I fix CVE-2025-27240?
To fix CVE-2025-27240, ensure your Zabbix instance is updated to the latest version where the vulnerability is patched.
3
What are the potential impacts of CVE-2025-27240?
The potential impacts of CVE-2025-27240 include unauthorized data manipulation and access to sensitive information stored in the database.
4
Who is affected by CVE-2025-27240?
CVE-2025-27240 affects administrators using Zabbix Server, particularly those who can modify host 'Visible name' fields.
5
Is CVE-2025-27240 being actively exploited?
At this time, there are no confirmed reports of active exploitation concerning CVE-2025-27240.