Junglewise Threat Intelligence

CVE-2026-23934: Zabbix Frontend denial of service via validate.api.exists

CVE-2026-23934 · Severity: medium · CVSS 6.5 · Published 2026-08-18

Technologies: Zabbix, Zabbix Frontend. Vendors: Zabbix.

Executive brief

Zabbix Frontend is a web-based monitoring and alerting platform used by organizations to track infrastructure health. An authenticated user can send specially crafted requests to the validate.api.exists endpoint, causing excessive CPU consumption on the webserver and making the monitoring system unresponsive to legitimate traffic.

Technical details

This vulnerability is a denial-of-service condition in the Zabbix Frontend validate.api.exists action caused by inefficient request processing. The attack requires authentication and involves sending crafted HTTP requests that trigger disproportionate CPU load on the Frontend webserver. An authenticated attacker can exploit this to make the monitoring interface unavailable. The vulnerability affects Zabbix Frontend versions 7.4.0 through 7.4.11 and has been patched in version 7.4.12.

Affected products

  • Zabbix Frontend 7.4.0 - 7.4.11

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: patched: Fixed in version 7.4.12

References

Related threats