CVE-2026-1199
EUVD-2026-6073318.08.2026, 13:17
Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent simultaneously, potentially allowing for more password guesses than intended.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| zabbix | zabbix | 6.0.0 ≤ 𝑥 < 6.0.47 |
| zabbix | zabbix | 7.0.0 ≤ 𝑥 < 7.0.28 |
| zabbix | zabbix | 7.4.0 ≤ 𝑥 < 7.4.12 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases