Executive brief
Zabbix's login protection mechanism, which limits the number of failed login attempts to prevent brute-force attacks, can be bypassed when multiple login requests are sent simultaneously. An attacker can perform more password guesses than the system is designed to allow, increasing the likelihood of a successful account compromise through credential guessing.
Technical details
This is a race condition vulnerability in the login lockout mechanism affecting Zabbix's API and Frontend components. The flaw occurs because unsuccessful login requests sent in parallel are not properly counted towards the brute-force block counter, allowing an attacker to exceed the intended threshold of failed attempts. An attacker with network access to the Zabbix Frontend or API can exploit this by sending concurrent login requests with different passwords. The vulnerability enables more password guesses than intended, significantly increasing the feasibility of brute-force attacks. Patches are available in versions 6.0.47, 7.0.28, and 7.4.12.
Affected products
- Zabbix Zabbix 6.0.0 - 6.0.46, 7.0.0 - 7.0.27, 7.4.0 - 7.4.11
Timeline
- 2026-08-18: disclosed
- 2026-08-18: patched: Fixed in versions 6.0.47, 7.0.28, and 7.4.12