What is CVE-2026-23933?
CVE-2026-23933 is a vulnerability in Zabbix 7.4 where the cryptographic key for signing Frontend sessions was erroneously written to the database seed. This primarily affects deployments using both SAML authentication and guest users, allowing attackers to forge valid sessions. Immediate patching is recommended for environments utilizing these features.
Azərbaycanca: CVE-2026-23933 Zabbix 7.4 versiyasında Frontend sessiyalarını imzalamaq üçün istifadə olunan kriptoqrafik açarın səhvən verilənlər bazası seed-inə yazılması zəifliyidir. Bu, xüsusilə həm SAML autentifikasiyası, həm də qonaq istifadəçilərdən istifadə edən quraşdırmalara təsir edir və təcavüzkarın etibarlı sessiyalar saxtalaşdırmasına imkan verir. Bu cür mühitlərdə Zabbix-in ən son patçlanmış versiyasına təcili yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: Zabbix
FAQ2
Which version of Zabbix does CVE-2026-23933 affect?
Zabbix version 7.4.
Which Zabbix deployments are particularly at risk for CVE-2026-23933?
Deployments using both SAML authentication and guest users.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.