The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://support.zabbix.com/browse/ZBX-28070 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-18 13:17
Updated : 2026-09-01 20:56
NVD link : CVE-2026-23931
Mitre link : CVE-2026-23931
CVE.ORG link : CVE-2026-23931
JSON object : View
Products Affected
No product.
CWE
CWE-203
Observable Discrepancy
