CVE 6.9 MEDIUM

Unauthenticated arbitrary PHP class instantiation_CVE-2026-23923

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Description

An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.

Basic Information

ID CVE-2026-23923
Source Zabbix
Published Mar 24, 2026 at 18:29
Modified Mar 25, 2026 at 19:25

Affected Product

Vendor Zabbix
Product Zabbix
Version 7.4.0
Affected Versions Zabbix Zabbix 7.4.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.