CVE-2026-23930

EUVD-2026-60735
An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service.
Amplification
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 26.9%
Affected Products (NVD)
VendorProductVersion
zabbixzabbix
6.0.0 ≤
𝑥
< 6.0.47
zabbixzabbix
7.0.0 ≤
𝑥
< 7.0.27
zabbixzabbix
7.4.0 ≤
𝑥
< 7.4.11
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
zabbix
bookworm
ignored
forky
1:7.0.29+dfsg-2
fixed
sid
1:7.0.29+dfsg-2
fixed
trixie
ignored
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
zabbix
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage