What is CVE-2026-1199?
A flaw in the Zabbix API and Frontend login lockout mechanism causes simultaneous unsuccessful login requests to not be properly counted towards the block counter, potentially allowing more password guesses than intended.
Azərbaycanca: Zabbix API və Frontend-in giriş kilidləmə mexanizmində qüsur aşkarlanıb. Eyni vaxtda göndərilən uğursuz giriş cəhdləri blok sayğacına düzgün əlavə olunmur ki, bu da nəzərdə tutulduğundan daha çox parol sınağına imkan verir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which components of Zabbix are affected by CVE-2026-1199?
CVE-2026-1199 affects the login lockout mechanism in the Zabbix API and Frontend components.
How can CVE-2026-1199 be exploited?
Simultaneous unsuccessful login requests are not properly counted towards the block counter, allowing an attacker to make more password guesses than intended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.