CVE-2026-23930: Frontend DoS via the popup.testtriggerexpr action
Published Aug 18, 2026
·Updated
An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service.
Event History
Aug 18, 2026
CVE Published
via MITRE·12:17 PM
Data Sourced
via MITRE·12:17 PM
RemedyDescriptionWeakness
Frequently Asked Questions
1
Who is realistically exposed to this issue?
Any deployment that exposes the Frontend webserver to unauthenticated requests may be exposed, because no authentication is required to send the crafted requests.
2
What does an attacker need to exploit it?
An attacker needs only to send specifically crafted requests to the Frontend popup.testtriggerexpr action. The described impact is disproportionate CPU consumption on the Frontend webserver, which can cause denial of service.