Session Management Vulnerability in Zabbix by Zabbix SIA
CVE-2026-23933
7.7HIGH
What is CVE-2026-23933?
A flaw in Zabbix 7.4 allows the cryptographic key used for signing Frontend sessions to be stored in the database seed. This vulnerability primarily affects deployments that utilize both SAML authentication and have guest users enabled. In these cases, attackers could leverage the key to create forged session cookies, leading to potential unauthorized access. Other deployments of Zabbix are currently not known to be affected.
Affected Version(s)
Zabbix 7.4.0 <= 7.4.10
References
CVSS V4
Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Zabbix wants to thank Daniel Shemesh and Or Ida for submitting this report on the HackerOne bug bounty platform.
