Use of Hard-coded Cryptographic Key in Zabbix - CVE-2026-23933

 

Use of Hard-coded Cryptographic Key in Zabbix - CVE-2026-23933

Published: August 18, 2026


Vulnerability identifier: #VU144188
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-23933
CWE-ID: CWE-321
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access.

The vulnerability exists due to use of a hardcoded cryptographic key in frontend session signing when handling SAML authentication with guest users enabled. A remote attacker can forge valid session cookies to gain unauthorized access.

The only known exploitation scenario affects deployments that use both SAML authentication and guest users. Other deployments do not have a known impact.


Affected software

Zabbix

How to mitigate CVE-2026-23933

Install security update from vendor's website.

Zabbix - update to 7.4.11

External References

Related Security Bulletins