Description
The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.
Published: 2026-08-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the frontend validate.api.exists API call in Zabbix allows an authenticated user to retrieve the plaintext values of user macros, potentially exposing sensitive configuration or credential data and causing confidentiality loss. The weakness aligns with CWE-203, Sensitive Information Exposure, as the data is exposed without proper authorization checks.

Affected Systems

The issue affects Zabbix products where the validate.api.exists action is implemented. No specific version numbers are listed, but the vendor advises applying the patched components available in the latest releases. Administrators should verify that their deployments include the unpatched frontend modules.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate impact. The EPSS is not available and the vulnerability is not listed in CISA's KEV catalog, suggesting no known widespread exploitation yet. The exploit requires valid user credentials, so any account with sufficient permissions could leverage it. The attack vector is thus through authenticated access to the Zabbix UI, extracting macro data before encryption or obfuscation is applied.

Generated by OpenCVE AI on August 18, 2026 at 13:51 UTC.

Remediation

Vendor Solution

Update the affected components to their respective fixed versions.


Vendor Workaround

Macro values with the 'Secret text' or 'Vault secret' types are not affected.


OpenCVE Recommended Actions

  • Update Zabbix to the fixed version(s) provided by the vendor.
  • Restrict user privileges to the minimum required for operation, limiting the set of authenticated users who can trigger the exploit.
  • Deploy or configure macro values as 'Secret text' or 'Vault secret' types, which are not affected by this issue.

Generated by OpenCVE AI on August 18, 2026 at 13:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Zabbix
Zabbix zabbix
Vendors & Products Zabbix
Zabbix zabbix

Tue, 18 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.
Title Frontend plaintext macro value enumeration via the validatate.api.exists action
Weaknesses CWE-203
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zabbix

Published:

Updated: 2026-08-18T13:35:23.212Z

Reserved: 2026-01-19T14:03:13.686Z

Link: CVE-2026-23931

cve-icon Vulnrichment

Updated: 2026-08-18T12:51:06.717Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T13:17:21.433

Modified: 2026-09-01T20:56:59.203

Link: CVE-2026-23931

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T14:15:07Z

Weaknesses