CVE-2026-23937

Summary

The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity.

Affected Software

VendorProductVersion RangeStatus
ZabbixZabbix6.0.0 <= 6.0.46affected
ZabbixZabbix7.0.0 <= 7.0.27affected
ZabbixZabbix7.4.0 <= 7.4.11affected

Weaknesses

  • CWE-203: CWE-203: Observable Discrepancy

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References