CVE-2026-23930 PUBLISHED

Frontend DoS via the popup.testtriggerexpr action

Assigner: Zabbix
Reserved: 19.01.2026 Published: 18.08.2026 Updated: 18.08.2026

An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor Zabbix
Product Zabbix
Versions Default: unknown
  • affected from 6.0.0 to 6.0.46 (incl.)
  • affected from 7.0.0 to 7.0.26 (incl.)
  • affected from 7.4.0 to 7.4.10 (incl.)

Affected Configurations

An unauthenticated user sending crafted HTTP requests to Zabbix Frontend.

Solutions

Update the affected components to their respective fixed versions.

Credits

  • Zabbix wants to thank barume for submitting this report on the HackerOne bug bounty platform. reporter

References

Problem Types

  • CWE-405: Asymmetric Resource Consumption (Amplification) CWE

Impacts

  • CAPEC-490: Amplification