zabbix
19 known vulnerabilities affecting zabbix products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-23921 | Medium | 3.5% | 8.8 | A low privilege Zabbix user with API access can exploit a blind SQL injection vu… | |
| CVE-2026-23933 | Medium | 0.4% | 9.1 | In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been … | |
| CVE-2026-23930 | Medium | 0.4% | 7.5 | An unauthenticated user is able to cause disproportionate CPU load on the Fronte… | |
| CVE-2026-23920 | Medium | 0.3% | 8.8 | Host and event action script input is validated with a regex (set by the adminis… | |
| CVE-2026-59781 | Medium | 0.1% | 7.8 | When Zabbix Agent was installed on Windows into a custom installation directory,… | |
| CVE-2026-23934 | Low | 0.4% | 6.5 | An authenticated user is able to cause disproportionate CPU load on the Frontend… | |
| CVE-2026-23935 | Low | 0.3% | 4.9 | A Zabbix administrator is able to read out of bounds memory by utilizing a flaw … | |
| CVE-2026-23938 | Low | 0.3% | 4.9 | An authenticated administrator is able to crash Zabbix server or proxy by creati… | |
| CVE-2026-23922 | Low | 0.3% | 4.9 | The email media OAuth field 'Client secret' cannot be read after saving, but a S… | |
| CVE-2026-23937 | Low | 0.3% | 6.5 | The Zabbix API host.get action can be exploited by authenticated users to extrac… | |
| CVE-2026-23923 | Low | 0.3% | 5.3 | An unauthenticated attacker can exploit the Frontend 'validate' action to blindl… | |
| CVE-2026-23926 | Low | 0.3% | 6.8 | An authenticated (non-super) administrator can create a maintenance period with … | |
| CVE-2026-23928 | Low | 0.3% | 6.8 | The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0… | |
| CVE-2026-23919 | Low | 0.2% | 6.0 | For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts… | |
| CVE-2026-23924 | Low | 0.2% | 4.9 | Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_in… | |
| CVE-2026-23927 | Low | 0.2% | 6.5 | A user able to connect to Agent 2 can inject an Oracle TNS connection string via… | |
| CVE-2026-23931 | Low | 0.2% | 4.3 | The frontend validatate.api.exists action can be exploited by authenticated user… | |
| CVE-2026-23929 | Low | 0.2% | 5.4 | Prototype pollution vulnerability in searchParamsToObject() is leading to a pers… | |
| CVE-2026-1199 | Low | 0.2% | 3.7 | Zabbix API and Frontend login lockout mechanism has a flaw where several unsucce… |