Improper access control in Zabbix - CVE-2026-23931
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the validate.api.exists action in the frontend when handling crafted HTTP requests. A remote user can send crafted HTTP requests to disclose sensitive information.
Plaintext user macro values can be extracted, while macro values of the 'Secret text' or 'Vault secret' types are not affected.