An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Update the affected components to their respective fixed versions.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.zabbix.com/browse/ZBX-27641 |
|
History
Tue, 24 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time. | |
| Title | Unauthenticated arbitrary PHP class instantiation | |
| Weaknesses | CWE-470 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Zabbix
Published:
Updated: 2026-03-24T18:29:23.165Z
Reserved: 2026-01-19T14:02:54.327Z
Link: CVE-2026-23923
No data.
Status : Received
Published: 2026-03-24T19:16:50.740
Modified: 2026-03-24T19:16:50.740
Link: CVE-2026-23923
No data.
OpenCVE Enrichment
No data.
Weaknesses