CVE-2026-23923

Publication date

2026-03-24 18:29:23

Family

Zabbix

State

PUBLISHED

Description

An unauthenticated attacker can exploit the Frontend validate action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.