---
id: CVE-2026-23930
title: >-
  An unauthenticated user is able to cause disproportionate CPU load on the
  Frontend webserver by sending specifically crafted requests to the Frontend
  popup.testtriggerexpr action, leading to potential denial of service.
summary: >-
  An unauthenticated user is able to cause disproportionate CPU load on the
  Frontend webserver by sending specifically crafted requests to the Frontend
  popup.testtriggerexpr action, leading to potential denial of service.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-405
vendor: zabbix
product: zabbix
affected:
  - 'zabbix >= 6.0.0, < 6.0.47'
  - 'zabbix >= 7.0.0, < 7.0.27'
  - 'zabbix >= 7.4.0, < 7.4.11'
patched:
  - zabbix 7.4.11
published: '2026-08-18'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T15:05:57.843'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-23930'
references:
  - url: 'https://support.zabbix.com/browse/ZBX-28069'
    label: security@zabbix.com
tags:
  - nvd
epss: 0.00355
epssPercentile: 0.29291
ingestedAt: '2026-09-08T15:33:26.953Z'
---

## Overview

An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service.

## Affected

- `zabbix >= 6.0.0, < 6.0.47`
- `zabbix >= 7.0.0, < 7.0.27`
- `zabbix >= 7.4.0, < 7.4.11`

## Remediation

Upgrade past the affected range:

- `zabbix 7.4.11`
