CVE Database
/

CVE-2026-23923

Back to search

CVE-2026-23923

Published: Mar 24, 2026

Modified: Mar 25, 2026

PUBLISHED

Description

An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.

VendorProductVersions

Zabbix

Zabbix

affected
7.4.0 - <= 7.4.6

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now