Session Management Vulnerability in Zabbix by Zabbix SIA
CVE-2026-23933

7.7HIGH

Key Information:

Vendor

Zabbix

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-23933?

A flaw in Zabbix 7.4 allows the cryptographic key used for signing Frontend sessions to be stored in the database seed. This vulnerability primarily affects deployments that utilize both SAML authentication and have guest users enabled. In these cases, attackers could leverage the key to create forged session cookies, leading to potential unauthorized access. Other deployments of Zabbix are currently not known to be affected.

Affected Version(s)

Zabbix 7.4.0 <= 7.4.10

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zabbix wants to thank Daniel Shemesh and Or Ida for submitting this report on the HackerOne bug bounty platform.
.