CVE-2026-23921 | Zabbix up to 7.0.21/7.2.14/7.4.5 CApiService.php sortfield sql injection (EUVD-2026-14955)
A vulnerability was found in Zabbix up to 7.0.21/7.2.14/7.4.5. It has been classified as critical. This affects an unknown function of the file include/classes/api/CApiService.php. Performing a manipulation of the argument sortfield results in sql injection.
This vulnerability was named CVE-2026-23921. The attack may be initiated remotely. There is no available exploit.