CVE-2026-23923: Unauthenticated arbitrary PHP class instantiation
Published Mar 24, 2026
·Updated
An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.
Affected Software
1 affected component
Zabbix Zabbix>=7.4.0<7.4.7
Event History
Mar 24, 2026
CVE Published
via MITRE·06:29 PM
Data Sourced
via MITRE·06:29 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated attacker can exploit it remotely through the Frontend 'validate' action. No privileges or user interaction are required.
2
What conditions affect the impact?
The impact depends on the PHP classes and broader environment setup available to the affected deployment. The available information indicates that impact appears limited at this time.
3
What security effect is confirmed by the available information?
The reported effect is blind instantiation of arbitrary PHP classes. The supplied CVSS vector indicates an availability impact of low, with no confirmed confidentiality or integrity impact.