← All Advisories

CVE-2026-23933

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-23933

Key Details

CVECVE-2026-23933
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-09-23
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none.
Affected productszabbix zabbix
Classified asCWE-259 (Use of Hard-coded Password)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
zabbixzabbix
SubsystemsGeneral OT
SectorsMultiple

What to Know

In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that utilize both - SAML authentication and guest users. In such cases the key can be used to forge valid session cookies, potentially leading to unauthorized access. For other Zabbix deployments this does not have a known impact. (NVD)

What to Do

Monitor zabbix's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-23933
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-23933
Vendor advisoryhttps://support.zabbix.com/browse/ZBX-28071