Description
The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity.
Published: 2026-08-18
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Zabbix API host.get action can be abused by authenticated users to read a host’s pre‑shared key (PSK). Exposure of the PSK undermines data integrity, allowing an attacker to forge or tamper with encrypted traffic to the monitored host, potentially corrupting configuration or metrics data. The weakness is an information exposure flaw (CWE‑203).

Affected Systems

Zabbix products are affected. Specific product names are ‘Zabbix’ as identified by the CNA. No version details are provided in the advisory, so any Zabbix installation that exposes the host.get API to authenticated users may be vulnerable.

Risk and Exploitability

The CVSS score of 6.0 indicates a medium severity, and the EPSS score is not available. The vulnerability is not listed in CISA KEV, suggesting it is not a known widely‑used exploit. The attack requires valid authentication to the Zabbix API, so the risk depends on how strictly API credentials are protected. If an attacker succeeds, they can compromise data integrity of monitored hosts but remote code execution is not directly supported by the flaw.

Generated by OpenCVE AI on August 18, 2026 at 14:16 UTC.

Remediation

Vendor Solution

Update the affected components to their respective fixed versions.


OpenCVE Recommended Actions

  • Apply the latest Zabbix version that fixes the PSK extraction flaw.
  • Limit the host.get API access to only trusted, minimally privileged accounts.
  • Rotate any pre‑shared keys that may have been exposed and enforce strong credential policies.

Generated by OpenCVE AI on August 18, 2026 at 14:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Zabbix
Zabbix zabbix
Vendors & Products Zabbix
Zabbix zabbix

Tue, 18 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity.
Title Host PSK extraction in Zabbix API
Weaknesses CWE-203
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zabbix

Published:

Updated: 2026-08-18T13:34:46.556Z

Reserved: 2026-01-19T14:03:13.686Z

Link: CVE-2026-23937

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T13:17:21.973

Modified: 2026-08-18T14:17:01.677

Link: CVE-2026-23937

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T14:30:05Z

Weaknesses