The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.
An authenticated user sending crafted HTTP requests to Zabbix Frontend.
Macro values with the 'Secret text' or 'Vault secret' types are not affected.
Update the affected components to their respective fixed versions.