---
id: CVE-2026-23934
title: >-
  An authenticated user is able to cause disproportionate CPU load on the
  Frontend webserver by sending specifically crafted requests to the Frontend
  validate.api.exists action, leading to potential denial of service.
summary: >-
  An authenticated user is able to cause disproportionate CPU load on the
  Frontend webserver by sending specifically crafted requests to the Frontend
  validate.api.exists action, leading to potential denial of service.
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-405
vendor: zabbix
product: zabbix
affected:
  - 'zabbix >= 7.4.0, < 7.4.12'
patched:
  - zabbix 7.4.12
published: '2026-08-18'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T14:30:27.420'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-23934'
references:
  - url: 'https://support.zabbix.com/browse/ZBX-28072'
    label: security@zabbix.com
tags:
  - nvd
epss: 0.00169
epssPercentile: 0.06576
ingestedAt: '2026-09-23T15:26:23.403Z'
---

## Overview

An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading to potential denial of service.

## Affected

- `zabbix >= 7.4.0, < 7.4.12`

## Remediation

Upgrade past the affected range:

- `zabbix 7.4.12`
