Zabbix 6.0.x < 6.0.48 Multiple Vulnerabilities

high Web App Scanning Plugin ID 115508

Synopsis

Zabbix 6.0.x < 6.0.48 Multiple Vulnerabilities

Description

According to its self-reported version number, the version of Zabbix running on the remote host is 6.0.x prior to 6.0.48, or 7.0.x prior to 7.0.29, or 7.4.x prior to 7.4.13. It is, therefore, affected by multiple vulnerabilities :

- A prototype pollution vulnerability in searchParamsToObject() leading to a persistent cross-site scripting (XSS) in Maps, as URL parameter processing did not filter dangerous properties such as __proto__, combined with an unsafe jQuery element creation that traversed the prototype chain. (CVE-2026-23929)

- A hardcoded session key, as in Zabbix 7.4 the cryptographic key used for signing frontend sessions was erroneously written to the database seed. In deployments using both SAML authentication and guest users, the key can be used to forge valid session cookies, potentially leading to unauthorized access. (CVE-2026-23933)

- A denial of service vulnerability, as an unauthenticated user is able to cause disproportionate CPU load on the frontend webserver by sending specifically crafted requests to the popup.testtriggerexpr action. (CVE-2026-23930)

- A denial of service vulnerability, as an authenticated user is able to cause disproportionate CPU load on the frontend webserver by sending specifically crafted requests to the validate.api.exists action. (CVE-2026-23934)

- An information disclosure vulnerability, as the frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values. (CVE-2026-23931)

- An information disclosure vulnerability, as the API host.get action can be exploited by authenticated users to extract a host's PSK key, leading to a potential loss of data integrity. (CVE-2026-23937)

- An out-of-bounds read vulnerability, as a Zabbix administrator is able to read out of bounds memory by utilizing a flaw in the script item/preprocessing (JavaScript) HttpRequest logic. (CVE-2026-23935)

- A race condition in the API and frontend login lockout mechanism, where several unsuccessful login requests are not properly counted towards the block counter if sent simultaneously, potentially allowing for more password guesses than intended. (CVE-2026-1199)

- An insufficiently protected credentials vulnerability, as the email media OAuth 'Client secret' field cannot be read after saving but can be leaked by a Super Admin setting a malicious 'Token endpoint'. (CVE-2026-23922)

- A denial of service vulnerability, as an authenticated administrator is able to crash the Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts. (CVE-2026-23938)

- An uncontrolled search path element vulnerability, as the Windows agent installer did not verify whether a custom installation directory had secure access permissions, increasing the risk of DLL sideloading. (CVE-2026-59781)

Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Zabbix version 6.0.48 or later.

See Also

https://www.zabbix.com/security_advisories?query=ZBV-2026-08-18-1

https://www.zabbix.com/security_advisories?query=ZBV-2026-08-18-10

https://www.zabbix.com/security_advisories?query=ZBV-2026-08-18-11

https://www.zabbix.com/security_advisories?query=ZBV-2026-08-18-2

https://www.zabbix.com/security_advisories?query=ZBV-2026-08-18-3

https://www.zabbix.com/security_advisories?query=ZBV-2026-08-18-4

https://www.zabbix.com/security_advisories?query=ZBV-2026-08-18-5

https://www.zabbix.com/security_advisories?query=ZBV-2026-08-18-6

https://www.zabbix.com/security_advisories?query=ZBV-2026-08-18-7

https://www.zabbix.com/security_advisories?query=ZBV-2026-08-18-8

https://www.zabbix.com/security_advisories?query=ZBV-2026-08-18-9

Plugin Details

Severity: High

ID: 115508

Type: Version Based

Published: 9/23/2026

Updated: 9/23/2026

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.74

CVSS v2

Risk Factor: High

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-23930

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CVSS Score Source: CVE-2026-23933

CVSS v4

Risk Factor: High

Base Score: 8.5

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-23929

Vulnerability Information

CPE: cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*

Exploit Ease: No known exploits are available

Patch Publication Date: 8/18/2026

Vulnerability Publication Date: 8/17/2026

Reference Information

CVE: CVE-2026-1199, CVE-2026-23922, CVE-2026-23929, CVE-2026-23930, CVE-2026-23931, CVE-2026-23933, CVE-2026-23934, CVE-2026-23935, CVE-2026-23937, CVE-2026-23938, CVE-2026-59781

CWE: 125, 1321, 203, 248, 259, 362, 405, 427, 522

OWASP: 2010-A3, 2010-A4, 2010-A6, 2013-A2, 2013-A4, 2013-A5, 2013-A9, 2017-A5, 2017-A6, 2017-A9, 2021-A4, 2021-A6, 2021-A7, 2021-A8, 2025-A10, 2025-A6, 2025-A7, 2025-A8

WASC: Application Misconfiguration, Denial of Service, Insufficient Authorization

CAPEC: 1, 102, 180, 26, 29, 38, 474, 50, 509, 540, 551, 555, 560, 561, 600, 644, 645, 652, 653, 77

DISA STIG: APSC-DV-002560, APSC-DV-002590, APSC-DV-002630

HIPAA: 164.306(a)(1), 164.306(a)(2), 164.312(a)(1), 164.312(e)

ISO: 27001-A.12.6.1, 27001-A.13.1.3, 27001-A.13.2.1, 27001-A.14.1.2, 27001-A.14.1.3, 27001-A.14.2.5, 27001-A.9.2.1, 27001-A.9.2.4, 27001-A.9.3.1, 27001-A.9.4.3

NIST: sp800_53-AC-4, sp800_53-CM-6b, sp800_53-IA-5, sp800_53-SC-24, sp800_53-SI-16

OWASP API: 2019-API7, 2019-API8, 2023-API8

OWASP ASVS: 4.0.2-12.3.1, 4.0.2-14.2.1, 4.0.2-5.3.1

PCI-DSS: 3.2-12.3, 3.2-2.1, 3.2-2.2, 3.2-6.2, 3.2-6.5, 3.2-6.5.10, 3.2-6.5.2, 3.2-6.5.8, 3.2-8.1, 3.2-8.2, 3.2-8.5, 3.2-8.6