CVE-2026-23923

MEDIUM

Unauthenticated arbitrary PHP class instantiation

Title source: cna
STIX 2.1

Description

An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.

References (1)

Core 1

Scores

CVSS v4 6.9
EPSS 0.0029
EPSS Percentile 20.1%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-470
Status published
Products (1)
Zabbix/Zabbix 7.4.0 - 7.4.6
Published Mar 24, 2026
Tracked Since Mar 25, 2026