The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.
Advisories
No advisories yet.
Fixes
Solution
Update the affected components to their respective fixed versions.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.zabbix.com/browse/ZBX-28067 |
|
History
Tue, 18 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zabbix
Zabbix zabbix |
|
| Vendors & Products |
Zabbix
Zabbix zabbix |
Tue, 18 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint. | |
| Title | Email media OAuth secret leak to Super Admin | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Zabbix
Published:
Updated: 2026-08-18T12:13:38.438Z
Reserved: 2026-01-19T14:02:54.327Z
Link: CVE-2026-23922
No data.
Status : Received
Published: 2026-08-18T13:17:21.040
Modified: 2026-08-18T13:17:21.040
Link: CVE-2026-23922
No data.
OpenCVE Enrichment
Updated: 2026-08-18T14:15:07Z
Weaknesses