CVE-2026-23937
Zabbix Server vulnerability analysis and mitigation

Overview

CVE-2026-23937 is a PSK key extraction vulnerability in the Zabbix API's host.get action that allows authenticated users to retrieve a host's Pre-Shared Key (PSK), leading to potential loss of data integrity. It affects Zabbix versions 6.0.0–6.0.46, 7.0.0–7.0.27, and 7.4.0–7.4.11. The vulnerability was disclosed on August 18, 2026, and assigned a CVSS v4.0 base score of 6.0 (Medium) (Zabbix Support, EUVD).

Technical details

The root cause is classified as CWE-203 (Observable Discrepancy), where the Zabbix API's host.get action inadvertently exposes sensitive PSK key material to authenticated callers. An attacker with low-privileged authenticated access to the Zabbix API can send crafted HTTP requests to the host.get endpoint to extract PSK keys. Exploitation additionally requires access to the Zabbix trapper port, introducing an attack requirement (AT:P) that slightly limits exploitability. No public PoC code has been identified at this time (Zabbix Support).

Impact

Successful exploitation allows an authenticated attacker to extract PSK keys used for encrypted communication between Zabbix components, primarily impacting data integrity (CVSS VI:High) and to a lesser extent confidentiality (CVSS VC:Low). An attacker in possession of a host's PSK could impersonate monitored hosts or tamper with monitoring data sent over the Zabbix trapper protocol, potentially undermining the reliability of the entire monitoring infrastructure. Availability is not directly impacted (Zabbix Support).

Exploitability

No active in-the-wild exploitation has been reported, and the EPSS score is currently 0.0. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is not automatable (per NVD SSVC assessment) and requires an authenticated user account with access to the host.get API action as well as network access to the Zabbix trapper port, limiting the practical attack surface (Zabbix Support).

Exploitation steps

  1. Authenticate to Zabbix API: Obtain valid low-privileged credentials for the Zabbix instance and authenticate via the API (e.g., POST /api_jsonrpc.php with user.login method) to receive an API session token.
  2. Identify target hosts: Use the host.get API method with the session token to enumerate hosts configured with PSK-based encryption.
  3. Craft malicious host.get request: Send a crafted HTTP request to the Zabbix API host.get action with parameters designed to extract PSK key fields that should not be returned to the caller.
  4. Extract PSK key: Parse the API response to retrieve the exposed PSK key material for the targeted host.
  5. Abuse PSK for trapper access: With the extracted PSK, gain access to the Zabbix trapper port to impersonate the monitored host, inject falsified monitoring data, or intercept communications, compromising monitoring integrity (Zabbix Support).

Indicators of compromise

  • Network: Unusual or repeated API calls to the Zabbix host.get endpoint from low-privileged user accounts, particularly with output fields requesting encryption/PSK-related parameters; unexpected connections to the Zabbix trapper port from non-agent IP addresses.
  • Logs: Zabbix API access logs showing host.get requests with atypical field selections (e.g., PSK-related output fields) from accounts not normally performing host enumeration; authentication events from unfamiliar source IPs.
  • Process/Behavior: Monitoring data anomalies such as unexpected metric values or host check-ins from known hosts at unusual times, which may indicate PSK-based impersonation of monitored agents (Zabbix Support).

Mitigation and workarounds

Zabbix has released fixed versions addressing this vulnerability: 6.0.47 (for the 6.0.x branch), 7.0.28 (for the 7.0.x branch), and 7.4.12 (for the 7.4.x branch). No workarounds are provided by the vendor; upgrading to the respective fixed version is the only recommended remediation. Organizations should also review API access controls to ensure only necessary accounts have access to the host.get action, and restrict network access to the Zabbix trapper port to trusted agent IPs (Zabbix Support).

Additional resources


SourceThis report was generated using AI

Related Zabbix Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23935MEDIUM6.8
  • Zabbix Server logoZabbix Server
  • zabbix
NoNoAug 18, 2026
CVE-2026-23937MEDIUM6
  • Zabbix Server logoZabbix Server
  • zabbix
NoNoAug 18, 2026
CVE-2026-59781MEDIUM5.4
  • Zabbix Server logoZabbix Server
  • zabbix
NoNoAug 18, 2026
CVE-2026-23934MEDIUM5.1
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoNoAug 18, 2026
CVE-2026-23938LOW2.1
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoNoAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management