CVE-2026-23922
EUVD-2026-6073118.08.2026, 13:17
The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| zabbix | zabbix | 7.4.0 ≤ 𝑥 ≤ 7.4.8 | CNA |
Common Weakness Enumeration