CVE-2026-1199
Received Received - Intake

Brute Force Login Bypass in Zabbix API

Vulnerability report for CVE-2026-1199, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-18

Last updated on: 2026-08-18

Assigner: Zabbix

Description

Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent simultaneously, potentially allowing for more password guesses than intended.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-18
Last Modified
2026-08-18
Generated
2026-08-18
AI Q&A
2026-08-18
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zabbix zabbix *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-362 The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Zabbix API and Frontend allows multiple simultaneous login attempts to bypass the lockout mechanism. Normally, failed login attempts should increment a block counter to prevent brute force attacks, but this flaw lets attackers send several requests at once without proper counting, enabling more password guesses than intended.

Impact Analysis

An attacker could exploit this to perform brute force attacks on Zabbix accounts, potentially gaining unauthorized access. This could lead to data breaches, system compromise, or unauthorized control over monitored systems if admin credentials are obtained.

Compliance Impact

This vulnerability could lead to unauthorized access, violating data protection requirements under GDPR and HIPAA. Organizations may face compliance penalties, reputational damage, and increased risk of data exposure if the flaw is exploited.

Mitigation Strategies

Apply the latest Zabbix security patch or update to fix the login lockout mechanism flaw. Monitor login attempts for unusual activity and enforce stricter rate limiting if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-1199. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart