The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity.
Advisories
No advisories yet.
Fixes
Solution
Update the affected components to their respective fixed versions.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.zabbix.com/browse/ZBX-28074 |
|
History
Tue, 18 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zabbix
Zabbix zabbix |
|
| Vendors & Products |
Zabbix
Zabbix zabbix |
Tue, 18 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity. | |
| Title | Host PSK extraction in Zabbix API | |
| Weaknesses | CWE-203 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Zabbix
Published:
Updated: 2026-08-18T13:34:46.556Z
Reserved: 2026-01-19T14:03:13.686Z
Link: CVE-2026-23937
No data.
Status : Received
Published: 2026-08-18T13:17:21.973
Modified: 2026-08-18T14:17:01.677
Link: CVE-2026-23937
No data.
OpenCVE Enrichment
Updated: 2026-08-18T14:30:05Z
Weaknesses