CVE-2026-23931 PUBLISHED

Frontend plaintext macro value enumeration via the validatate.api.exists action

Assigner: Zabbix
Reserved: 19.01.2026 Published: 18.08.2026 Updated: 18.08.2026

The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor Zabbix
Product Zabbix
Versions Default: unknown
  • affected from 7.4.0 to 7.4.10 (incl.)

Affected Configurations

An authenticated user sending crafted HTTP requests to Zabbix Frontend.

Workarounds

Macro values with the 'Secret text' or 'Vault secret' types are not affected.

Solutions

Update the affected components to their respective fixed versions.

Credits

  • Zabbix wants to thank nidomer1 for submitting this report on the HackerOne bug bounty platform. reporter

References

Problem Types

  • CWE-203: Observable Discrepancy CWE

Impacts

  • CAPEC-122: Privilege Abuse