CVE-2026-23937 PUBLISHED

Host PSK extraction in Zabbix API

Assigner: Zabbix
Reserved: 19.01.2026 Published: 18.08.2026 Updated: 18.08.2026

The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6

Product Status

Vendor Zabbix
Product Zabbix
Versions Default: unknown
  • affected from 6.0.0 to 6.0.46 (incl.)
  • affected from 7.0.0 to 7.0.27 (incl.)
  • affected from 7.4.0 to 7.4.11 (incl.)

Affected Configurations

An authenticated user with access to host.get API action sending crafted HTTP requests to Zabbix API. An attacker would also need access to Zabbix trapper port.

Solutions

Update the affected components to their respective fixed versions.

References

Problem Types

  • CWE-203: Observable Discrepancy CWE

Impacts

  • CAPEC-122: Privilege Abuse