CVE-2026-23923

Source
https://cve.org/CVERecord?id=CVE-2026-23923
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23923.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-23923
Published
2026-03-24T19:16:50Z
Modified
2026-09-12T08:14:50Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
[none]
Details

An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.

References

Affected packages

Git / github.com/zabbix/zabbix

Affected ranges

Type
GIT
Repo
https://github.com/zabbix/zabbix
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "7.4.0"
        },
        {
            "fixed": "7.4.7"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

7.*
7.4.0
7.4.1
7.4.1rc1
7.4.2
7.4.2rc1
7.4.2rc2
7.4.3
7.4.3rc1
7.4.4
7.4.4rc1
7.4.5
7.4.6
7.4.6rc1
7.4.6rc2
7.4.7rc1
7.4.7rc2
7.4.7rc3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23923.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "325384714460559008211380272189886777379",
                "161202494417122568768003688957558185717",
                "78613746942143536196276371120859374090",
                "98679310835563898350721270856285671786",
                "113434350780301213082882425875976030982",
                "296560762299850979029643899112001044678"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-23923-234b3a70",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/zabbix/zabbix/commit/b033beafb23d83ecb4e90a9b6f9ea856e9215566",
        "target": {
            "file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
        }
    }
]
vanir_signatures_modified
"2026-09-12T08:14:50Z"