Login Lockout Flaw in Zabbix API and Frontend
CVE-2026-1199

6.9MEDIUM

Key Information:

Vendor

Zabbix

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-1199?

The Zabbix API and Frontend contain a vulnerability in its login lockout mechanism, where multiple failed login attempts sent simultaneously can bypass the expected block. This flaw allows an attacker to perform more password guesses than intended, potentially compromising user accounts through brute force attacks.

Affected Version(s)

Zabbix 6.0.0 <= 6.0.46

Zabbix 7.0.0 <= 7.0.27

Zabbix 7.4.0 <= 7.4.11

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zabbix wants to thank Vitaly Simonovich for submitting this report on the HackerOne bug bounty platform.
.