CVE-2026-23931: Zabbix

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.

Affected products

  • Zabbix Zabbix: from 7.4.0, before 7.4.11 (fixed in 7.4.11)

Published 2026-08-18. Last modified 2026-09-23.