← Back to CVE search

CVE-2026-23934

Zabbix

Description

An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading to potential denial of service.

CVSS 5.1EPSS 0.169%Risk 0.52
View source
Published
2026-08-18 13:17:21
Affected versions
unknown
Type
Web application
Last modified
2026-08-18 14:17:01
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X