CVE-2026-23933

NameCVE-2026-23933
DescriptionIn Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that utilize both - SAML authentication and guest users. In such cases the key can be used to forge valid session cookies, potentially leading to unauthorized access. For other Zabbix deployments this does not have a known impact.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
zabbix (PTS)bullseye1:5.0.8+dfsg-1fixed
bullseye (security)1:5.0.47+dfsg-0+deb11u1fixed
bookworm1:6.0.14+dfsg-1fixed
trixie1:7.0.22+dfsg-1~deb13u1fixed
sid1:7.0.22+dfsg-1.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
zabbixsource(unstable)(not affected)

Notes

- zabbix <not-affected> (Only affects 7.4.x)
https://support.zabbix.com/browse/ZBX-28071

Search for package or bug name: Reporting problems