Improper access control in Zabbix - CVE-2026-23937
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the host.get API action when handling crafted HTTP requests to the Zabbix API. A remote user can send crafted HTTP requests to extract a host's PSK key to disclose sensitive information.
Exploitation also requires access to the Zabbix trapper port.