Use of Hard-coded Cryptographic Key in Zabbix - CVE-2026-23933
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access.
The vulnerability exists due to use of a hardcoded cryptographic key in frontend session signing when handling SAML authentication with guest users enabled. A remote attacker can forge valid session cookies to gain unauthorized access.
The only known exploitation scenario affects deployments that use both SAML authentication and guest users. Other deployments do not have a known impact.