Race condition in Zabbix - CVE-2026-1199
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform more password guesses than intended.
The vulnerability exists due to a race condition in the login lockout mechanism in the frontend and api when processing simultaneous unsuccessful login requests. A remote attacker can send multiple concurrent login requests to perform more password guesses than intended.