Impact
In Zabbix 7.4 the key used to sign Frontend sessions is incorrectly stored in the database seed. The hard‑coded key can be extracted by an attacker who can then forge valid session cookies. When a deployment uses both SAML authentication and guest users this forgery permits unauthorized access to the web interface and may lead to privilege escalation, since the forged session is treated as a legitimate user session.
Affected Systems
All installations of Zabbix Server version 7.4 that have been configured with both SAML authentication and guest users are affected. The issue applies to the Zabbix product line as managed by the vendor Zabbix.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity, and the vulnerability is not currently listed in the CISA KEV catalog. The EPSS score is unavailable, so the current exploitation probability is unknown. Attackers would need to target a site with SAML authentication enabled and at least one guest account; upon obtaining the key from the database, they can craft a valid session cookie and impersonate a legitimate user. In the absence of these conditions the vulnerability has no known impact.
OpenCVE Enrichment