CVE-2026-23922
EUVD-2026-6073118.08.2026, 13:17
The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| zabbix | zabbix | 7.4.0 ≤ 𝑥 < 7.4.9 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration