CVE-2026-23922: Zabbix

Medium severity, CVSS 4.9. EPSS: 0.3% chance of exploitation in the next 30 days.

The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.

Affected products

  • Zabbix Zabbix: from 7.4.0, before 7.4.9 (fixed in 7.4.9)

Published 2026-08-18. Last modified 2026-09-08.