Junglewise Threat Intelligence

CVE-2026-23937: Zabbix API PSK key extraction in host.get

CVE-2026-23937 · Severity: medium · CVSS 6.5 · Published 2026-08-18

Technologies: Zabbix. Vendors: Zabbix.

Executive brief

Zabbix is a widely-deployed infrastructure monitoring platform. An authenticated user can exploit the API's host.get action to extract pre-shared key (PSK) credentials, compromising encrypted communications between Zabbix agents and the server. This undermines data integrity and confidentiality of monitoring data and enables unauthorized access to monitored systems.

Technical details

The vulnerability is an information disclosure flaw in the Zabbix API host.get action that improperly exposes sensitive PSK keys to authenticated users. An attacker must be authenticated to the Zabbix API and have access to the host.get action, and additionally requires network access to the Zabbix trapper port (typically 10051) to abuse the extracted credentials. By sending crafted HTTP requests, an attacker can retrieve PSK values that should be protected, enabling them to intercept or spoof agent communications. The issue affects Zabbix 6.0.0–6.0.46, 7.0.0–7.0.27, and 7.4.0–7.4.11, with fixes available in 6.0.47, 7.0.28, and 7.4.12 respectively.

Affected products

  • Zabbix Zabbix 6.0.0–6.0.46, 7.0.0–7.0.27, 7.4.0–7.4.11

Timeline

  • 2026-08-18: disclosed: CVE-2026-23937 published
  • 2026-08-18: patched: Fixes released: 6.0.47, 7.0.28, 7.4.12

References

Related threats