Zabbix 7.4 hardcoded frontend session key (CVE-2026-23933)
Zabbix's 18 August 2026 advisory (ZBX-28071) says that in Zabbix 7.4 the cryptographic key used for signing frontend sessions was erroneously written to the database seed. The only known exploitation scenario is deployments that use both SAML authentication and guest users: the key can be used to forge valid session cookies and gain unauthorised frontend access. Other deployments have no known impact. Affected: 7.4.0 through 7.4.10. Fixed: 7.4.11. Vendor CVSS 4.0 is 7.7 (High). Workaround: clear settings.session_key in the Zabbix database so the frontend generates a new random key. Zabbix credited Daniel Shemesh and Or Ida via HackerOne. Not in CISA KEV at last check.
- Product
- Zabbix Server / Frontend 7.4
- Versions
- 7.4.0 through 7.4.10
- CVSS
- (CVSS 4.0, Zabbix)
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - Exploited in Australia?
- unknown
- Patch to
- 7.4.11 (or clear settings.session_key as a workaround)
Primary: Zabbix ZBX-28071 · Vendor: Zabbix (vendor) · CVE: CVE-2026-23933 · CVE-2026-23933
