The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23931.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"80225613835803133910910126596852952088",
"230058783349080063223687654489728332059",
"177878195683979894346014332267148188511",
"188349145695577399953969866264285031573",
"329342636515519127775980169026149266987",
"58272670197979715614362102333779585045"
],
"threshold": 0.9
},
"id": "CVE-2026-23931-a8156f50",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zabbix/zabbix/commit/a6a1f80f9dd9c9461513853ecabc5b1a6c7dd521",
"target": {
"file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
}
}
]
"2026-09-25T08:11:22Z"