ExportXMLWordPrintable

    • Type: Defect (Security)
    • Resolution: Fixed
    • Priority: Minor
    • None
    • Affects Version/s: None
    • Component/s: API (A)
    • None

      CVE ID CVE-2026-23937
      CVSS score 6.0 (Medium)
      CVSS vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
      Affected components API
      Summary Host PSK extraction in Zabbix API
      Description The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity.
      Known attack vectors An authenticated user with access to host.get API action sending crafted HTTP requests to Zabbix API. An attacker would also need access to Zabbix trapper port.
      Affected and fix version/s Affected: 6.0.0 - 6.0.46 → Fixed: 6.0.47
      Affected: 7.0.0 - 7.0.27 → Fixed: 7.0.28
      Affected: 7.4.0 - 7.4.11 → Fixed: 7.4.12
      Mitigation Update the affected components to their respective fixed versions.
      Workarounds -

            Assignee:
            Zabbix Support Team
            Reporter:
            Janis Nulle
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: