CVE-2026-23933
Received Received - Intake

Session Cookie Forgery in Zabbix 7.4 via Database Seed Exposure

Vulnerability report for CVE-2026-23933, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-18

Last updated on: 2026-08-18

Assigner: Zabbix

Description

In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that utilize both - SAML authentication and guest users. In such cases the key can be used to forge valid session cookies, potentially leading to unauthorized access. For other Zabbix deployments this does not have a known impact.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-18
Last Modified
2026-08-18
Generated
2026-08-18
AI Q&A
2026-08-18
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zabbix zabbix 7.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-259 The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

In Zabbix 7.4, a cryptographic key used for signing frontend sessions was mistakenly stored in the database seed. This flaw primarily affects deployments using both SAML authentication and guest users, allowing potential forgery of session cookies and unauthorized access.

Detection Guidance

Detection requires checking if your Zabbix deployment uses both SAML authentication and guest users. Review database entries for the cryptographic key in the seed field and inspect session cookie generation for anomalies.

Impact Analysis

If you use Zabbix 7.4 with SAML authentication and guest users enabled, attackers could forge session cookies to gain unauthorized access. Other deployments are not known to be affected.

Compliance Impact

The vulnerability may impact compliance with GDPR or HIPAA only in specific Zabbix deployments using SAML authentication and guest users. Unauthorized access from forged session cookies could lead to data breaches, violating confidentiality requirements under these regulations.

Mitigation Strategies

Rotate the cryptographic key used for session signing immediately. Disable guest user access if SAML is enabled. Update to a patched Zabbix version if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-23933. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart