Description
The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.
Published: 2026-08-18
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Zabbix email media OAuth configuration allows a Super Admin to expose the client secret by setting a malicious token endpoint. After the client secret is entered and saved, it is normally not retrievable, but the vulnerability permits a privileged user to redirect the token retrieval process to an attacker‑controlled server, thus leaking the secret. This could enable credential theft and unauthorized OAuth token usage, representing a loss of confidentiality for the integration.

Affected Systems

The affected product is Zabbix, specifically the email media OAuth configuration. No version range is provided in the advisory, so any deployment that uses the email media OAuth feature should be evaluated for applicability.

Risk and Exploitability

The CVSS score of 2.1 indicates a low overall impact, and the issue is not listed in the CISA KEV catalog. The likelihood of exploitation relies on a Super Admin having the ability to change the token endpoint. Because the attacker must be a privileged administrator, the opportunity for external attackers is limited. The EPSS score is not available, but the vulnerability remains a concern for internal threat actors with administrative access.

Generated by OpenCVE AI on August 18, 2026 at 13:53 UTC.

Remediation

Vendor Solution

Update the affected components to their respective fixed versions.


OpenCVE Recommended Actions

  • Update Zabbix to the latest version that fixes the OAuth client secret leak.
  • Verify that any changes to the email media token endpoint are made only to trusted endpoints and roll back any suspicious modifications.
  • Restrict Super Admin privilege or enforce configuration checks to prevent unauthorized token endpoint changes.

Generated by OpenCVE AI on August 18, 2026 at 13:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Zabbix
Zabbix zabbix
Vendors & Products Zabbix
Zabbix zabbix

Tue, 18 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.
Title Email media OAuth secret leak to Super Admin
Weaknesses CWE-522
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zabbix

Published:

Updated: 2026-08-18T16:02:15.215Z

Reserved: 2026-01-19T14:02:54.327Z

Link: CVE-2026-23922

cve-icon Vulnrichment

Updated: 2026-08-18T16:02:12.051Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T13:17:21.040

Modified: 2026-09-01T20:56:59.203

Link: CVE-2026-23922

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T14:15:07Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials