EIP-2026-114562

PRE-CVE

Zabbix 2.0 < 3.0.3 - SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-114562. PoCs published by Zzzians.

AI-analyzed exploit summary This Python script exploits a SQL injection vulnerability in Zabbix versions 2.0 to 3.0.3 by injecting malicious SQL queries into the 'profileIdx2' parameter. It extracts user credentials and session IDs from the database.

Description

Zabbix 2.0 < 3.0.3 - SQL Injection

Exploits (1)

exploitdb WORKING POC
by Zzzians · pythonwebappsphp
https://www.exploit-db.com/exploits/40353

This Python script exploits a SQL injection vulnerability in Zabbix versions 2.0 to 3.0.3 by injecting malicious SQL queries into the 'profileIdx2' parameter. It extracts user credentials and session IDs from the database.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Zabbix 2.0 to 3.0.3
No auth needed
Prerequisites: Network access to the Zabbix web interface · Zabbix version between 2.0 and 3.0.3
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026