
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23937 is a PSK key extraction vulnerability in the Zabbix API's host.get action that allows authenticated users to retrieve a host's Pre-Shared Key (PSK), leading to potential loss of data integrity. It affects Zabbix versions 6.0.0–6.0.46, 7.0.0–7.0.27, and 7.4.0–7.4.11. The vulnerability was disclosed on August 18, 2026, and assigned a CVSS v4.0 base score of 6.0 (Medium) (Zabbix Support, EUVD).
The root cause is classified as CWE-203 (Observable Discrepancy), where the Zabbix API's host.get action inadvertently exposes sensitive PSK key material to authenticated callers. An attacker with low-privileged authenticated access to the Zabbix API can send crafted HTTP requests to the host.get endpoint to extract PSK keys. Exploitation additionally requires access to the Zabbix trapper port, introducing an attack requirement (AT:P) that slightly limits exploitability. No public PoC code has been identified at this time (Zabbix Support).
Successful exploitation allows an authenticated attacker to extract PSK keys used for encrypted communication between Zabbix components, primarily impacting data integrity (CVSS VI:High) and to a lesser extent confidentiality (CVSS VC:Low). An attacker in possession of a host's PSK could impersonate monitored hosts or tamper with monitoring data sent over the Zabbix trapper protocol, potentially undermining the reliability of the entire monitoring infrastructure. Availability is not directly impacted (Zabbix Support).
No active in-the-wild exploitation has been reported, and the EPSS score is currently 0.0. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is not automatable (per NVD SSVC assessment) and requires an authenticated user account with access to the host.get API action as well as network access to the Zabbix trapper port, limiting the practical attack surface (Zabbix Support).
POST /api_jsonrpc.php with user.login method) to receive an API session token.host.get API method with the session token to enumerate hosts configured with PSK-based encryption.host.get action with parameters designed to extract PSK key fields that should not be returned to the caller.host.get endpoint from low-privileged user accounts, particularly with output fields requesting encryption/PSK-related parameters; unexpected connections to the Zabbix trapper port from non-agent IP addresses.host.get requests with atypical field selections (e.g., PSK-related output fields) from accounts not normally performing host enumeration; authentication events from unfamiliar source IPs.Zabbix has released fixed versions addressing this vulnerability: 6.0.47 (for the 6.0.x branch), 7.0.28 (for the 7.0.x branch), and 7.4.12 (for the 7.4.x branch). No workarounds are provided by the vendor; upgrading to the respective fixed version is the only recommended remediation. Organizations should also review API access controls to ensure only necessary accounts have access to the host.get action, and restrict network access to the Zabbix trapper port to trusted agent IPs (Zabbix Support).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."