
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23934 is a denial-of-service vulnerability in the Zabbix Frontend component, specifically in the validate.api.exists action. An authenticated user can send specially crafted HTTP requests to this endpoint, causing disproportionate CPU load on the Frontend web server. The vulnerability affects Zabbix versions 7.4.0 through 7.4.11, with a fix available in version 7.4.12. It carries a CVSS v4.0 base score of 5.1 (Medium) (Zabbix Advisory).
The root cause is classified as CWE-405 (Asymmetric Resource Consumption / Amplification), where a low-cost attacker request triggers disproportionately high server-side CPU processing. The attack vector is adjacent network (AV:A), requires low privileges (an authenticated user account), and no user interaction. An attacker crafts specific HTTP requests targeting the validate.api.exists Frontend action, which causes the web server to consume excessive CPU resources relative to the input provided (Zabbix Advisory).
Successful exploitation results in degraded availability of the Zabbix Frontend web server due to excessive CPU consumption, potentially rendering the monitoring interface unresponsive or slow for legitimate users. There is no impact on confidentiality or integrity — the vulnerability is limited to an availability impact classified as Low at the vulnerable component level. Because Zabbix is a monitoring platform, disruption of its Frontend could impair visibility into infrastructure health during an attack (Zabbix Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the disclosure date. The NVD SSVC assessment indicates exploitation status as "none" and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is 0.0, reflecting a very low probability of near-term exploitation. Exploitation requires a valid authenticated session on the Zabbix Frontend, limiting the attack surface to users with existing credentials (Zabbix Advisory).
validate.api.exists Frontend action endpoint.validate.api.exists endpoint from a single authenticated session or IP address.validate.api.exists action with unusual or crafted parameters.Zabbix has released version 7.4.12 as the fixed release for affected versions 7.4.0 through 7.4.11. Administrators should upgrade the Zabbix Frontend to version 7.4.12 or later as the primary remediation. No official workarounds are provided by the vendor; upgrading is the recommended and only documented mitigation (Zabbix Advisory).
The vulnerability was reported to Zabbix through the HackerOne bug bounty platform by researcher "kang999" and was acknowledged by Zabbix in their official issue tracker. No significant broader media coverage or notable community commentary has been identified beyond the vendor's advisory (Zabbix Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."