Vulnerability
Published 2026-08-18
Verified 2026-09-19

Zabbix 7.4 hardcoded frontend session key (CVE-2026-23933)

Zabbix's 18 August 2026 advisory (ZBX-28071) says that in Zabbix 7.4 the cryptographic key used for signing frontend sessions was erroneously written to the database seed. The only known exploitation scenario is deployments that use both SAML authentication and guest users: the key can be used to forge valid session cookies and gain unauthorised frontend access. Other deployments have no known impact. Affected: 7.4.0 through 7.4.10. Fixed: 7.4.11. Vendor CVSS 4.0 is 7.7 (High). Workaround: clear settings.session_key in the Zabbix database so the frontend generates a new random key. Zabbix credited Daniel Shemesh and Or Ida via HackerOne. Not in CISA KEV at last check.

Product
Zabbix Server / Frontend 7.4
Versions
7.4.0 through 7.4.10
CVSS
(CVSS 4.0, Zabbix)
Exploited in Australia?
unknown
Patch to
7.4.11 (or clear settings.session_key as a workaround)

Primary: Zabbix ZBX-28071 · Vendor: Zabbix (vendor) · CVE: CVE-2026-23933 · CVE-2026-23933

vulnerabilities