Status: UPDATED
| Advisory ID: CVE-2026-23933
Key Details
| CVE | CVE-2026-23933 |
| CVSS Score / Version | 9.1 (Critical) / CVSS v3.1 |
| Updated | 2026-09-23 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none. |
| Affected products | zabbix zabbix |
| Classified as | CWE-259 (Use of Hard-coded Password) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that utilize both - SAML authentication and guest users. In such cases the key can be used to forge valid session cookies, potentially leading to unauthorized access. For other Zabbix deployments this does not have a known impact. (NVD)
What to Do
Monitor zabbix's web page for any future patch releases. See vendor advisory link below.
References