Login Lockout Flaw in Zabbix API and Frontend
CVE-2026-1199
6.9MEDIUM
What is CVE-2026-1199?
The Zabbix API and Frontend contain a vulnerability in its login lockout mechanism, where multiple failed login attempts sent simultaneously can bypass the expected block. This flaw allows an attacker to perform more password guesses than intended, potentially compromising user accounts through brute force attacks.
Affected Version(s)
Zabbix 6.0.0 <= 6.0.46
Zabbix 7.0.0 <= 7.0.27
Zabbix 7.4.0 <= 7.4.11
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Zabbix wants to thank Vitaly Simonovich for submitting this report on the HackerOne bug bounty platform.
