CVE-2026-23923

EUVD-2026-14956
An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.
Unsafe Reflection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 16.8%
Affected Products (NVD)
VendorProductVersion
zabbixzabbix
7.4.0 ≤
𝑥
< 7.4.7
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
zabbix
bookworm
1:6.0.14+dfsg-1
fixed
forky
1:7.0.29+dfsg-2
fixed
sid
1:7.0.29+dfsg-2
fixed
trixie
1:7.0.22+dfsg-1~deb13u1
fixed