CVE-2026-23931

Summary

The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.

Affected Software

VendorProductVersion RangeStatus
ZabbixZabbix7.4.0 <= 7.4.10affected

Weaknesses

  • CWE-203: CWE-203: Observable Discrepancy

Workarounds

Macro values with the 'Secret text' or 'Vault secret' types are not affected.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References