Junglewise Threat Intelligence

CVE-2026-23933: Zabbix Frontend session key disclosure in database

CVE-2026-23933 · Severity: critical · CVSS 9.1 · Published 2026-08-18

Technologies: Zabbix, Zabbix Frontend. Vendors: Zabbix.

Executive brief

Zabbix 7.4 stores the cryptographic key used to sign web interface session cookies in the database, where it can be read by attackers. This allows unauthorized users to forge valid session cookies and gain administrative access to the monitoring platform. The vulnerability only affects deployments using both SAML authentication and guest user access.

Technical details

The vulnerability is a cryptographic key exposure flaw in Zabbix 7.4 where the session signing key is written to the database seed instead of being randomly generated per deployment. An unauthenticated attacker with network access to the Zabbix frontend can read this key from the database and use it to forge valid session cookies. Exploitation is most practical on deployments that enable both SAML authentication and guest user access. The affected versions are 7.4.0 through 7.4.10; the fix is available in 7.4.11 and later. Workaround: manually clear the 'settings.session_key' database value to force regeneration of a random key.

Affected products

  • Zabbix Zabbix Server 7.4.0 to 7.4.10
  • Zabbix Zabbix Frontend 7.4.0 to 7.4.10

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: patched: Fixed in version 7.4.11

References

Related threats