CVE-2024-42327

CRITICAL

Zabbix 6.0.0-6.0.32 - Authenticated SQL Injection via CUser.addRelatedObjects

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 13 public exploits for CVE-2024-42327. PoCs published by m4nb4, BridgerAlderson, iSee857.

AI-analyzed exploit summary This script checks for SQL injection vulnerability (CVE-2024-42327) in Zabbix by attempting a time-based SQLi test. It authenticates with the target, sends a crafted request with a SLEEP payload, and determines vulnerability based on the response.

Description

A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function which is available for every user who has API access.

Exploits (13)

exploitdb SCANNER
by m4nb4 · pythonwebappsphp
https://www.exploit-db.com/exploits/52230

This script checks for SQL injection vulnerability (CVE-2024-42327) in Zabbix by attempting a time-based SQLi test. It authenticates with the target, sends a crafted request with a SLEEP payload, and determines vulnerability based on the response.

Classification
Scanner 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Zabbix 6.0.0-6.0.31, 6.4.0-6.4.16, 7.0.0
Auth required
Prerequisites: Valid Zabbix credentials · Access to Zabbix API endpoint
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 46 stars
by BridgerAlderson · poc
https://github.com/BridgerAlderson/Zabbix-CVE-2024-42327-SQL-Injection-RCE

This repository contains a functional exploit for CVE-2024-42327, a SQL injection vulnerability in Zabbix's CUser class. The exploit uses time-based SQL injection to extract admin session IDs and then leverages the Zabbix API to execute a reverse shell command.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Zabbix (version not specified)
Auth required
Prerequisites: Valid Zabbix user credentials · Access to Zabbix API
devstral-2 · analyzed Feb 18, 2026 Full analysis →
github WORKING POC 40 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/Zabbix(CVE-2024-42327).py

The repository contains functional exploit code for multiple CVEs, including CVE-2026-22812, which demonstrates a command execution vulnerability in OpenCode. The script sends crafted requests to exploit the vulnerability and verify command execution via the 'id' command.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: OpenCode (version not specified)
No auth needed
Prerequisites: Network access to the target · Target running vulnerable OpenCode instance
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec WORKING POC 36 stars
by aramosf · poc
https://github.com/aramosf/cve-2024-42327

This script exploits CVE-2024-42327 in Zabbix by abusing the JSON-RPC API to fetch sensitive user information, including passwords, by iterating over user IDs after authenticating with valid credentials.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Zabbix (version not specified, but referenced as ZBX-25623)
Auth required
Prerequisites: Valid Zabbix credentials · Access to the Zabbix JSON-RPC API endpoint
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 17 stars
by compr00t · poc
https://github.com/compr00t/CVE-2024-42327

This repository contains a functional PoC for CVE-2024-42327, an SQL injection vulnerability in Zabbix's CUser class. The exploit leverages a time-based SQLi in the 'selectRole' parameter of the 'user.get' API endpoint, demonstrating the vulnerability with a SLEEP-based payload.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Zabbix 6.0.31
Auth required
Prerequisites: Valid Zabbix user credentials with API access
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 9 stars
by godylockz · poc
https://github.com/godylockz/CVE-2024-42327

This repository contains a functional exploit for CVE-2024-42327, a critical SQL injection vulnerability in Zabbix servers. The exploit leaks the admin API token via blind SQLi and achieves RCE by creating a malicious item with a reverse shell payload.

Classification
Working Poc 95%
Attack Type
Sqli | Rce
Complexity
Moderate
Reliability
Reliable
Target: Zabbix < 6.0.32rc1, 6.4.17rc1, 7.0.1rc1
Auth required
Prerequisites: Valid Zabbix user credentials with API access
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 3 stars
by watchdog1337 · poc
https://github.com/watchdog1337/CVE-2024-42327_Zabbix_SQLI

This repository contains a functional Python exploit for CVE-2024-42327, an authenticated SQL injection vulnerability in Zabbix. The exploit leverages the `user.get` API endpoint to extract user credentials, session tokens, and execute custom SQL queries.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Zabbix (versions 6.0.0-6.0.31, 6.4.0-6.4.16, 7.0.0)
Auth required
Prerequisites: Valid Zabbix credentials with API access · Network access to the Zabbix API endpoint
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 3 stars
by depers-rus · poc
https://github.com/depers-rus/CVE-2024-42327

This repository contains a functional Python exploit for CVE-2024-42327, a SQL injection vulnerability in Zabbix's CUser class. The PoC demonstrates time-based SQLi and data exfiltration via the 'selectRole' parameter in the user.get API method.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Zabbix 6.0.0-6.0.31, 6.4.0-6.4.16, 7.0.0
Auth required
Prerequisites: Valid Zabbix user credentials with API access · Network access to Zabbix frontend
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC 1 stars
by 874anthony · poc
https://github.com/874anthony/CVE-2024-42327_Zabbix_SQLi

This repository contains a functional Python exploit for CVE-2024-42327, an authenticated SQL injection vulnerability in Zabbix 7.0.0. The script supports multiple modes, including user data extraction, session token leaks, remote command execution via reverse shell, and custom SQL query injection.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Zabbix 7.0.0
Auth required
Prerequisites: Valid Zabbix credentials · Network access to the Zabbix API endpoint
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WRITEUP
by RichJJ98 · poc
https://github.com/RichJJ98/analise-vulnerabilidades-zabbix-notebooklm

This repository provides a detailed technical analysis of SQL injection vulnerabilities in Zabbix, focusing on CVE-2024-42327 and related CVEs. It includes root cause analysis, attack chains, and hardening recommendations, but does not contain functional exploit code.

Classification
Writeup 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Theoretical
Target: Zabbix (multiple versions)
Auth required
Prerequisites: Access to Zabbix API with minimal privileges · Knowledge of SQL injection techniques
devstral-2 · analyzed Jun 10, 2026 Full analysis →
nomisec WORKING POC
by fellipefelix06 · poc
https://github.com/fellipefelix06/Zabbix-CVE-2024-42327

This exploit leverages Zabbix's API to create and execute a malicious script on a target host, achieving remote code execution via a reverse shell. It interacts with the Zabbix API to list hosts, create a script with a reverse shell payload, and execute it on the target host.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Zabbix (version not specified)
Auth required
Prerequisites: Valid Zabbix API token · Access to Zabbix API endpoint · Network connectivity to the target host
devstral-2 · analyzed May 17, 2026 Full analysis →
nomisec WORKING POC
by itform-fr · poc
https://github.com/itform-fr/Zabbix---CVE-2024-42327

This PoC exploits a SQL injection vulnerability in Zabbix's CUser.php to extract admin session tokens and user credentials, then executes arbitrary commands via script creation. It supports reverse shell payloads and credential enumeration.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Zabbix (version not specified)
Auth required
Prerequisites: Valid Zabbix user credentials · Network access to Zabbix API endpoint
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WRITEUP
by igorbf495 · poc
https://github.com/igorbf495/CVE-2024-42327

This repository provides a detailed technical analysis of CVE-2024-42327, focusing on privilege escalation in Zabbix via API abuse. It includes step-by-step exploitation details, code snippets, and API request examples to demonstrate how a low-privileged user can escalate to administrator by manipulating user group assignments.

Classification
Writeup 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Zabbix 7.0.0
Auth required
Prerequisites: Valid low-privileged Zabbix user credentials · Access to Zabbix API
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 9.9
EPSS 0.9146
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
zabbix/zabbix 6.0.0 - 6.0.32
Published Nov 27, 2024
Tracked Since Feb 18, 2026