What is CVE-2026-23937?
CVE-2026-23937 is a vulnerability in the Zabbix monitoring system. Authenticated users can exploit the `host.get` API action to extract a host's PSK key, potentially leading to a loss of data integrity.
Azərbaycanca: CVE-2026-23937 Zabbix monitorinq sistemində aşkar edilmiş boşluqdur. Autentifikasiya olunmuş istifadəçilər `host.get` API çağırışı vasitəsilə host-a məxsus PSK açarını əldə edə bilər. Bu, məlumat bütövlüyünün pozulmasına səbəb ola bilər.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Does exploiting CVE-2026-23937 require authentication to the Zabbix system?
Yes, this vulnerability can be exploited by an authenticated user.
Which API action in Zabbix allows the PSK key to be retrieved in CVE-2026-23937?
Through the `host.get` API action.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.