Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-23933: Zabbix 7.4 can let attackers create fake login cookies
CVE-2026-23933 · published 1 month ago
Summary
Zabbix version 7.4 stores a secret key in the database that should stay hidden. If you use both SAML login and allow guest users, an attacker could use that key to make a fake session cookie and gain access without permission. Update Zabbix to a version that corrects this or disable the guest/SAML combination until patched.
What to do
- Update zabbix zabbix to version 7.4.11.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | zabbix | zabbix |
<= 7.4.10 >= 7.4.0, < 7.4.11 Fix: upgrade to 7.4.11
|
| Ubuntu:Pro:14.04:LTS | canonical | zabbix | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | zabbix | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | zabbix | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | zabbix | All versions |
| Ubuntu:Pro:22.04:LTS | canonical | zabbix | All versions |
| Ubuntu:26.04:LTS | canonical | zabbix | All versions |
Original advisory text
In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that util...
In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that utilize both - SAML authentication and guest users. In such cases the key can be used to forge valid session cookies, potentially leading to unauthorized access. For other Zabbix deployments this does not have a known impact.
References
- https://support.zabbix.com/browse/ZBX-28071 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-23933 Third Party Advisory
- https://ubuntu.com/security/CVE-2026-23933 Third Party Advisory
Severity
9.4
Critical
CVSS 4.0: 9.4 (OSV)
Exploitation
EPSS <1%
Type
CWE-259Use of Hard-coded Password
Timeline
Published18 Aug 2026
Updated27 Sep 2026
First seen18 Aug 2026
Sources
UBUNTU-CVE-2026-23933 · OSV
CVE-2026-23933 · NVD
CVE-2026-23933 · MITRE
CVE-2026-23933 · OSV
Track software like this
Free during beta