Public Security Advisories

Proof of Possession.

Coordinated vulnerability disclosures from Argus. Findings, impact, and remediation, published in good faith.

1
Advisories
1
Critical
0
High
2026
Latest

Disclosed

1
  • CRITICAL Won't Fix

    SQL Injection via OAuth2 Token Refresh Response

    Zabbix server takes access_token and refresh_token values directly from an external OAuth server's HTTP response and interpolates them into a SQL UPDATE with no escaping. Stacked queries are enabled, giving an attacker who controls the token endpoint arbitrary SQL execution against the Zabbix database.

    Zabbix / Zabbix Server#sqli#oauth

Under Embargo

0
  • // No embargoed advisories.