ExportXMLWordPrintable

    • Type: Defect (Security)
    • Resolution: Fixed
    • Priority: Minor
    • None
    • Affects Version/s: None
    • Component/s: Frontend (F)
    • None

      CVE ID CVE-2026-23931
      CVSS score 5.3 (Medium)
      CVSS vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
      Affected components Frontend
      Summary Frontend plaintext macro value enumeration via the validatate.api.exists action
      Description The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.
      Known attack vectors An authenticated user sending crafted HTTP requests to Zabbix Frontend.
      Affected and fix version/s Affected: 7.4.0 - 7.4.10 → Fixed: 7.4.11
      Mitigation Update the affected components to their respective fixed versions.
      Workarounds Macro values with the 'Secret text' or 'Vault secret' types are not affected.
      Acknowledgements Zabbix wants to thank nidomer1 for submitting this report on the HackerOne bug bounty platform.

            Assignee:
            Zabbix Support Team
            Reporter:
            Janis Nulle
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: