nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-23923 CVE-2026-23923
MEDIUM
Unauthenticated arbitrary PHP class instantiation
Record summary
CVE-2026-23923 has a selected CVSS score of 6.9 (medium).
Description
An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 25, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ZabbixBrowse Zabbix / ZabbixDefault status: unknown | CVE List | 7.4.0 to ≤ 7.4.6 | affected |
References
2support.zabbix.com
https://support.zabbix.com/browse/ZBX-27641