← back
CVE-2026-23923mediumCWE-470

Unauthenticated arbitrary PHP class instantiation

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.9epss 0.3%
exploitation probability
0.3%top 81% of all CVEs
observed exploitation
nono source reports it
An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Affected products
Zabbix · Zabbix