CVE-2026-23934
- EPSS 0.17%
- Veröffentlicht 18.08.2026 12:18:53
- Zuletzt bearbeitet 23.09.2026 14:30:27
An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading to potential denial of service.
CVE-2026-23933
- EPSS 0.2%
- Veröffentlicht 18.08.2026 12:18:09
- Zuletzt bearbeitet 23.09.2026 14:31:46
In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that utilize both - SAML authentication and guest users. In su...
CVE-2026-23931
- EPSS 0.28%
- Veröffentlicht 18.08.2026 12:17:38
- Zuletzt bearbeitet 23.09.2026 14:38:36
The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.
CVE-2026-23930
- EPSS 0.17%
- Veröffentlicht 18.08.2026 12:17:01
- Zuletzt bearbeitet 08.09.2026 15:05:57
An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service.
CVE-2026-23929
- EPSS 0.3%
- Veröffentlicht 18.08.2026 12:16:15
- Zuletzt bearbeitet 08.09.2026 15:10:20
Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation that traversed the prot...
CVE-2026-1199
- EPSS 0.24%
- Veröffentlicht 18.08.2026 12:15:29
- Zuletzt bearbeitet 08.09.2026 15:25:05
Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent simultaneously, potentially allowing for more password guesses than intended.
CVE-2026-23922
- EPSS 0.28%
- Veröffentlicht 18.08.2026 12:13:38
- Zuletzt bearbeitet 08.09.2026 15:18:34
The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.
CVE-2026-23928
- EPSS 0.29%
- Veröffentlicht 06.05.2026 08:16:03
- Zuletzt bearbeitet 18.09.2026 15:19:05
The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard conta...
CVE-2026-23927
- EPSS 0.23%
- Veröffentlicht 06.05.2026 08:16:02
- Zuletzt bearbeitet 18.09.2026 15:26:56
A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a named sessio...
CVE-2026-23926
- EPSS 0.29%
- Veröffentlicht 06.05.2026 08:16:01
- Zuletzt bearbeitet 18.09.2026 15:35:11
An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unau...