The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Update the affected components to their respective fixed versions.
Workaround
Macro values with the 'Secret text' or 'Vault secret' types are not affected.
References
| Link | Providers |
|---|---|
| https://support.zabbix.com/browse/ZBX-28070 |
|
History
Tue, 18 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zabbix
Zabbix zabbix |
|
| Vendors & Products |
Zabbix
Zabbix zabbix |
Tue, 18 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality. | |
| Title | Frontend plaintext macro value enumeration via the validatate.api.exists action | |
| Weaknesses | CWE-203 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Zabbix
Published:
Updated: 2026-08-18T13:35:23.212Z
Reserved: 2026-01-19T14:03:13.686Z
Link: CVE-2026-23931
No data.
Status : Received
Published: 2026-08-18T13:17:21.433
Modified: 2026-08-18T14:17:01.157
Link: CVE-2026-23931
No data.
OpenCVE Enrichment
Updated: 2026-08-18T14:15:07Z
Weaknesses