An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading to potential denial of service.
Advisories
No advisories yet.
Fixes
Solution
Update the affected components to their respective fixed versions.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.zabbix.com/browse/ZBX-28072 |
|
History
Tue, 18 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zabbix
Zabbix zabbix |
|
| Vendors & Products |
Zabbix
Zabbix zabbix |
Tue, 18 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading to potential denial of service. | |
| Title | Frontend DoS via the validate.api.exists action | |
| Weaknesses | CWE-405 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Zabbix
Published:
Updated: 2026-08-18T13:35:07.131Z
Reserved: 2026-01-19T14:03:13.686Z
Link: CVE-2026-23934
No data.
Status : Received
Published: 2026-08-18T13:17:21.717
Modified: 2026-08-18T14:17:01.440
Link: CVE-2026-23934
No data.
OpenCVE Enrichment
Updated: 2026-08-18T14:15:07Z
Weaknesses