An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading to potential denial of service.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23934.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"162185643356969056099637373121662685754",
"301884150383061037293106834306734767993",
"63167804984895644221201641958791481105",
"38852671883870847759498189347652476358",
"282755891262507678007721094843042318317",
"41809926521244952597844054970073719247"
],
"threshold": 0.9
},
"id": "CVE-2026-23934-bd62128e",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zabbix/zabbix/commit/63588e12eb23a212c837dbbacb005949673b353a",
"target": {
"file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
}
}
]
"2026-09-25T08:11:21Z"