An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23923.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"325384714460559008211380272189886777379",
"161202494417122568768003688957558185717",
"78613746942143536196276371120859374090",
"98679310835563898350721270856285671786",
"113434350780301213082882425875976030982",
"296560762299850979029643899112001044678"
],
"threshold": 0.9
},
"id": "CVE-2026-23923-234b3a70",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zabbix/zabbix/commit/b033beafb23d83ecb4e90a9b6f9ea856e9215566",
"target": {
"file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
}
}
]
"2026-09-12T08:14:50Z"