Junglewise Threat Intelligence

CVE-2026-23931: Zabbix Frontend plaintext macro value enumeration

CVE-2026-23931 · Severity: medium · CVSS 4.3 · Published 2026-08-18

Technologies: Zabbix, Zabbix Frontend. Vendors: Zabbix.

Executive brief

Zabbix Frontend contains a vulnerability in its validatate.api.exists action that allows authenticated users to extract plaintext values of user-configured macros through crafted HTTP requests. This could expose sensitive configuration data and credentials stored as macro values, compromising the security of monitoring and automation configurations.

Technical details

The vulnerability is an information disclosure flaw in the Zabbix Frontend's validatate.api.exists API action. Authenticated users can exploit this by sending crafted HTTP requests to enumerate and extract plaintext values of user macros. The attack requires valid authentication credentials but no additional user interaction. Macro values configured with 'Secret text' or 'Vault secret' types are protected and not vulnerable. The vulnerability affects versions 7.4.0 through 7.4.10, with a fix available in version 7.4.11 and later.

Affected products

  • Zabbix Zabbix Frontend 7.4.0 to 7.4.10

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: patched: Fix released in version 7.4.11

References

Related threats