#VU124619 Deserialization of Untrusted Data in Zabbix - CVE-2026-23923
Published: March 25, 2026
Zabbix
Zabbix
Description
The vulnerability allows a remote attacker to instantiate arbitrary PHP classes.
The vulnerability exists due to improper input validation in the Frontend 'validate' action when handling requests. A remote attacker can send a specially crafted request to instantiate arbitrary PHP classes.
The impact depends on the environment setup but appears limited at this time.