CVE-2026-23923
Unauthenticated arbitrary PHP class instantiation
An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Affected products
Zabbix · ZabbixWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →