---
id: CVE-2026-23923
title: >-
  An unauthenticated attacker can exploit the Frontend 'validate' action to
  blindly instantiate arbitrary PHP classes
summary: >-
  An unauthenticated attacker can exploit the Frontend 'validate' action to
  blindly instantiate arbitrary PHP classes. The impact depends on environment
  setup but appears limited at this time.
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-470
vendor: zabbix
product: zabbix
affected:
  - 'zabbix >= 7.4.0, < 7.4.7'
patched:
  - zabbix 7.4.7
published: '2026-03-24'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T21:16:44.433'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-23923'
references:
  - url: 'https://support.zabbix.com/browse/ZBX-27641'
    label: security@zabbix.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-03-25T19:24:53.942052Z'
scores:
  nvd: 5.3
  cna: 6.9
ingestedAt: '2026-09-12T18:49:50.576Z'
epss: 0.00268
epssPercentile: 0.19179
---

## Overview

An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.

## Affected

- `zabbix >= 7.4.0, < 7.4.7`

## Remediation

Upgrade past the affected range:

- `zabbix 7.4.7`
