An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://support.zabbix.com/browse/ZBX-28069 |
|
History
Tue, 08 Sep 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 18 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zabbix
Zabbix zabbix |
|
| Vendors & Products |
Zabbix
Zabbix zabbix |
Tue, 18 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service. | |
| Title | Frontend DoS via the popup.testtriggerexpr action | |
| Weaknesses | CWE-405 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Zabbix
Published: 2026-08-18T12:17:01.795Z
Updated: 2026-08-18T13:35:30.857Z
Reserved: 2026-01-19T14:03:13.686Z
Link: CVE-2026-23930
No data.
Status : Analyzed
Published: 2026-08-18T13:17:21.303
Modified: 2026-09-08T15:05:57.843
Link: CVE-2026-23930
No data.