CVE-2026-23937

Source
https://cve.org/CVERecord?id=CVE-2026-23937
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23937.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-23937
Downstream
Published
2026-08-18T13:17:21Z
Modified
2026-09-25T08:11:22Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity.

References

Affected packages

Git / github.com/zabbix/zabbix

Affected ranges

Type
GIT
Repo
https://github.com/zabbix/zabbix
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "6.0.0"
        },
        {
            "fixed":  "6.0.47"
        },
        {
            "introduced":  "7.0.0"
        },
        {
            "fixed":  "7.0.28"
        },
        {
            "introduced":  "7.4.0"
        },
        {
            "fixed":  "7.4.12"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

6.*
6.0.0
6.0.1
6.0.10
6.0.10rc1
6.0.10rc2
6.0.11
6.0.11rc1
6.0.11rc2
6.0.12
6.0.12rc1
6.0.12rc2
6.0.13
6.0.13rc1
6.0.14
6.0.14rc1
6.0.14rc2
6.0.15
6.0.15rc1
6.0.15rc2
6.0.16
6.0.16rc1
6.0.17
6.0.17rc1
6.0.17rc2
6.0.18
6.0.18rc1
6.0.19
6.0.19rc1
6.0.1rc1
6.0.1rc2
6.0.1rc3
6.0.1rc4
6.0.2
6.0.20
6.0.20rc1
6.0.21
6.0.21rc1
6.0.22
6.0.22rc1
6.0.23
6.0.23rc1
6.0.25
6.0.25rc1
6.0.26
6.0.26rc1
6.0.27
6.0.27rc1
6.0.28
6.0.28rc1
6.0.29
6.0.29rc1
6.0.2rc1
6.0.3
6.0.30
6.0.30rc1
6.0.31
6.0.31rc1
6.0.32
6.0.32rc1
6.0.33
6.0.33rc1
6.0.34
6.0.34rc1
6.0.34rc2
6.0.35
6.0.35rc1
6.0.36
6.0.36rc1
6.0.37
6.0.37rc1
6.0.38
6.0.38rc1
6.0.39
6.0.39rc1
6.0.3rc1
6.0.4
6.0.40
6.0.40rc1
6.0.41
6.0.41rc1
6.0.42
6.0.42rc1
6.0.43
6.0.43rc1
6.0.44
6.0.44rc1
6.0.45
6.0.45rc1
6.0.46
6.0.46rc1
6.0.47rc1
6.0.4rc1
6.0.5
6.0.5rc1
6.0.6
6.0.6rc1
6.0.7
6.0.7rc1
6.0.8
6.0.8rc1
6.0.8rc2
6.0.9
6.0.9rc1
6.0.9rc2
7.*
7.0.0
7.0.1
7.0.10
7.0.10rc1
7.0.11
7.0.11rc1
7.0.11rc2
7.0.12
7.0.12rc1
7.0.13
7.0.13rc1
7.0.14
7.0.14rc1
7.0.15
7.0.16
7.0.17
7.0.17rc1
7.0.17rc2
7.0.18
7.0.18rc1
7.0.18rc2
7.0.19
7.0.19rc1
7.0.1rc1
7.0.1rc2
7.0.2
7.0.20
7.0.20rc1
7.0.21
7.0.22
7.0.22rc1
7.0.22rc2
7.0.22rc3
7.0.23
7.0.23rc1
7.0.23rc2
7.0.24
7.0.24rc1
7.0.24rc2
7.0.24rc3
7.0.25
7.0.25rc1
7.0.26
7.0.26rc1
7.0.27
7.0.27rc1
7.0.28rc1
7.0.2rc1
7.0.2rc2
7.0.3
7.0.3rc1
7.0.4
7.0.4rc1
7.0.5
7.0.5rc1
7.0.6
7.0.6rc1
7.0.7
7.0.7rc1
7.0.8
7.0.8rc1
7.0.8rc2
7.0.9
7.0.9rc1
7.0.9rc2
7.4.0
7.4.1
7.4.10
7.4.10rc1
7.4.11
7.4.11rc1
7.4.11rc2
7.4.12rc1
7.4.1rc1
7.4.2
7.4.2rc1
7.4.2rc2
7.4.3
7.4.3rc1
7.4.4
7.4.4rc1
7.4.5
7.4.6
7.4.6rc1
7.4.6rc2
7.4.7
7.4.7rc1
7.4.7rc2
7.4.7rc3
7.4.8
7.4.8rc1
7.4.8rc2
7.4.8rc3
7.4.9
7.4.9rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23937.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "61950285254057822375511809511230316649",
                "202208457591449445730552017254530970731",
                "22806171998387866034443206406648060655",
                "124374908236790130710091146456556061826",
                "210859921065700170806321554218079188008",
                "230192658099312171426732252572302441243"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-23937-87d0c2f8",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/zabbix/zabbix/commit/39db3e7dce42aca1f772888804eb3280627347f0",
        "target":  {
            "file":  "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "61950285254057822375511809511230316649",
                "202208457591449445730552017254530970731",
                "87894419954128763062683451642395375506",
                "186804029496176350787882414147569633402",
                "304471405615492947362739159760616706422",
                "302942259006478842191540169962906161704"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-23937-923668f2",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/zabbix/zabbix/commit/86f12eab5094d8a8cdea298a0b40210f6b219f34",
        "target":  {
            "file":  "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "162185643356969056099637373121662685754",
                "301884150383061037293106834306734767993",
                "63167804984895644221201641958791481105",
                "38852671883870847759498189347652476358",
                "282755891262507678007721094843042318317",
                "41809926521244952597844054970073719247"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-23937-bd62128e",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/zabbix/zabbix/commit/63588e12eb23a212c837dbbacb005949673b353a",
        "target":  {
            "file":  "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
        }
    }
]
vanir_signatures_modified
"2026-09-25T08:11:22Z"