CVE-2026-23937Medium· 6.5▾ SunlitThe Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity.
zabbix >= 6.0.0, < 6.0.47zabbix >= 7.0.0, < 7.0.28zabbix >= 7.4.0, < 7.4.12Upgrade past the affected range:
zabbix 7.4.12Connected by shared product, vendor, weakness, or advisory.
CVE-2026-23931Medium· 4.3The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.
CVE-2026-59781High· 7.8When Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether the selected directory had secure access permissions
CVE-2026-23938Medium· 4.9An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service.
CVE-2026-23934Medium· 6.5An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading to potential denial of service.
CVE-2026-23933Critical· 9.1In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed
CVE-2026-23935Medium· 4.9A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.