CVE-2026-23930

An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service.
References
Link Resource
https://support.zabbix.com/browse/ZBX-28069 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-18 13:17

Updated : 2026-09-08 15:05


NVD link : CVE-2026-23930

Mitre link : CVE-2026-23930

CVE.ORG link : CVE-2026-23930


JSON object : View

Products Affected

zabbix

  • zabbix
CWE
CWE-405

Asymmetric Resource Consumption (Amplification)