SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-23937

MEDIUM · CVSS 6 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Authenticated users can exploit the Zabbix API's host.get action to retrieve a host's PSK key, which may compromise data integrity. Organizations using Zabbix should prioritize addressing this vulnerability to prevent unauthorized access to sensitive information.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-23937
Severity
MEDIUM
CVSS
6
EPSS
0.28%

Original NVD Description

The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity.