CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0320 [1.00] [M/H] Vulnerabilities resolved in Zabbix

unknownCVE-2026-1199CVE-2026-23922CVE-2026-23929CVE-2026-23930CVE-2026-23931CVE-2026-23933
Zabbix SIA has resolved multiple vulnerabilities in Zabbix, including the API, Frontend, script item and preprocessing components, and the Windows Agent installer. The vulnerabilities affect various components of Zabbix. - An issue in the login lockout mechanism causes multiple simultaneous failed login attempts to not be counted correctly, allowing an attacker to bypass the lockout and make more password attempts than intended. - In the OAuth configuration for email media, a Super Admin can reveal and modify the client secret through modifications to the 'Token endpoint'. - Prototype pollution in the searchParamsToObject() function leads to persistent cross-site scripting (XSS) via unsafe URL parameter processing and jQuery element creation. - The Frontend webserver contains an action (popup.testtriggerexpr) that can be misused by unauthenticated users to cause a denial of service (DoS) through excessive CPU load. - Authenticated users can read plaintext user macro values via the validate.api.exists action, exposing sensitive information. In Zabbix 7.4, a cryptographic key for signing Frontend sessions is incorrectly stored in the database seed, allowing session cookies to be forged when using SAML authentication and guest users. The validate.api.exists action can also lead to DoS through excessive CPU usage with specially crafted requests. - In the script item and preprocessing JavaScript HttpRequest logic, an administrator can read memory outside the intended boundaries, potentially leading to information leaks. - The API host.get action allows authenticated users to determine the pre-shared key (PSK) of a host, undermining data confidentiality and integrity. - An authenticated administrator can cause a DoS through specially crafted JavaScript scripts in preprocessing or script items by overloading server or pro

CSIRTS triage

What
Multiple vulnerabilities in Zabbix components including a broken login lockout mechanism, OAuth client secret exposure, prototype pollution leading to XSS, and unauthenticated DoS via popup.testtriggerexpr action.
Who is affected
Zabbix deployments using affected API, Frontend, script item, preprocessing, and Windows Agent components.
Urgency
Medium to high priority; multiple attack vectors including authentication bypass and DoS affect availability and confidentiality.
Action
Apply Zabbix security updates to resolve CVE-2026-1199, CVE-2026-23922, CVE-2026-23929, CVE-2026-23930, CVE-2026-23931, CVE-2026-23933, CVE-2026-23934, and CVE-2026-23935.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Zabbix

Get an email when a new Zabbix advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-08-20
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0320

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-1199coverage & exploitation statusNVD · CVE.org
CVE-2026-23922coverage & exploitation statusNVD · CVE.org
CVE-2026-23929coverage & exploitation statusNVD · CVE.org
CVE-2026-23930coverage & exploitation statusNVD · CVE.org
CVE-2026-23931coverage & exploitation statusNVD · CVE.org
CVE-2026-23933coverage & exploitation statusNVD · CVE.org
CVE-2026-23934coverage & exploitation statusNVD · CVE.org
CVE-2026-23935coverage & exploitation statusNVD · CVE.org
CVE-2026-23937coverage & exploitation statusNVD · CVE.org
CVE-2026-23938coverage & exploitation statusNVD · CVE.org
CVE-2026-59781coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from NCSC-NL Advisories