Zabbix是拉脱维亚Zabbix公司开源的一套开源的监控系统。该系统支持网络监控、服务器监控、云监控和应用监控等。 Zabbix 6.0.0版本至6.0.46版本、7.0.0版本至7.0.27版本和7.4.0版本至7.4.11版本存在竞争条件问题漏洞,该漏洞源于API和Frontend登录锁定机制存在竞争条件问题,多个不成功登录请求同时发送时未正确计入阻止计数器,可能导致比预期更多的密码猜测。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-23929 | 8.5 HIGH | Prototype pollution leading to stored XSS |
| CVE-2026-23933 | 7.7 HIGH | Hardcoded session key in Zabbix 7.4 |
| CVE-2026-23935 | 6.8 MEDIUM | Use-after-free read in script item/preprocessing HttpRequest body |
| CVE-2026-23937 | 6.0 MEDIUM | Host PSK extraction in Zabbix API |
| CVE-2026-59781 | 5.4 MEDIUM | Improper validation of custom installation directories on Windows could allow installation |
| CVE-2026-23931 | 5.3 MEDIUM | Frontend plaintext macro value enumeration via the validatate.api.exists action |
| CVE-2026-23930 | 5.3 MEDIUM | Frontend DoS via the popup.testtriggerexpr action |
| CVE-2026-23934 | 5.1 MEDIUM | Frontend DoS via the validate.api.exists action |
| CVE-2026-23938 | 2.1 LOW | Server DoS via JavaScript preprocessing or script items |
| CVE-2026-23922 | 2.1 LOW | Email media OAuth secret leak to Super Admin |
No comments yet