6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Description
An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.
Basic Information
ID
CVE-2026-23923
Source
Zabbix
Published
Mar 24, 2026 at 18:29
Modified
Mar 25, 2026 at 19:25
Affected Product
Vendor
Zabbix
Product
Zabbix
Version
7.4.0
Affected Versions
Zabbix Zabbix 7.4.0