Zabbix API Vulnerability Exposes Sensitive Data for Authenticated Users
CVE-2026-23937

6MEDIUM

Key Information:

Vendor

Zabbix

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-23937?

The Zabbix API's host.get function is vulnerable, allowing authenticated users to exploit the system and access sensitive PSK keys. This exposure can severely compromise data integrity and lead to unauthorized access to crucial information. It is essential for Zabbix users to apply necessary updates and mitigate this risk promptly.

Affected Version(s)

Zabbix 6.0.0 <= 6.0.46

Zabbix 7.0.0 <= 7.0.27

Zabbix 7.4.0 <= 7.4.11

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.