#1144945 zabbix: CVE-2026-23937

Package:
src:zabbix
Source:
src:zabbix
Submitter:
Salvatore Bonaccorso
Date:
2026-08-23 04:21:02 UTC
Severity:
normal
Tags:
#1144945#5
Date:
2026-08-20 17:23:05 UTC
From:
To:
Hi,

The following vulnerability was published for zabbix.

CVE-2026-23937[0]:
| The Zabbix API host.get action can be exploited by authenticated
| users to extract a host's PSK key leading to potential loss of data
| integrity.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-23937
https://www.cve.org/CVERecord?id=CVE-2026-23937
[1] https://support.zabbix.com/browse/ZBX-28074

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1144945#10
Date:
2026-08-23 04:19:14 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
zabbix, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1144945@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Dmitry Smirnov <onlyjob@debian.org> (supplier of updated zabbix package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 23 Aug 2026 13:31:05 +1000
Source: zabbix
Architecture: source
Version: 1:7.0.29+dfsg-1
Distribution: unstable
Urgency: medium
Maintainer: Dmitry Smirnov <onlyjob@debian.org>
Changed-By: Dmitry Smirnov <onlyjob@debian.org>
Closes: 1144944 1144945 1144946
Changes:
 zabbix (1:7.0.29+dfsg-1) unstable; urgency=medium
 .
   * New upstream release. (Closes: #1144944, #1144945,#1144946)
     + CVE-2026-1199 (fixed in 7.0.28)
     + CVE-2026-23937 (fixed in 7.0.28)
     + CVE-2026-23935 (fixed in 7.0.28)
   * rules: not calling "make css" any more due to FTBFS.
   * Reproducible build.
   * Build-Depends:
     + libdnsjava-java
Checksums-Sha1:
 9d14f883e9aecc644c33705c61f4f8e2e4e1d62c 4216 zabbix_7.0.29+dfsg-1.dsc
 5ef5e67e8f01b962d563055e502363e086e68341 13682504 zabbix_7.0.29+dfsg.orig-templates.tar.xz
 a1b55661534a4ac94870490022fb9c3763a8aeb4 927936 zabbix_7.0.29+dfsg.orig-vendor.tar.xz
 27f02ba892ed8bc9eb6e99ffcdc5cd80c2de341b 22849540 zabbix_7.0.29+dfsg.orig.tar.xz
 47865bdb1c19434fd1e190ffe74754af340dbd10 145456 zabbix_7.0.29+dfsg-1.debian.tar.xz
 4b1594ab33d30f042a22b8a4e687c81215e13019 20929 zabbix_7.0.29+dfsg-1_amd64.buildinfo
Checksums-Sha256:
 77b259e3ce6b668438f03543d776501c7bc770477e0bd046c8037d084fbe01b8 4216 zabbix_7.0.29+dfsg-1.dsc
 d44ca21bfe6a570d011b2d61e2e7101bca06c2a2c633273c1d8d1b881c96451b 13682504 zabbix_7.0.29+dfsg.orig-templates.tar.xz
 d0a309bfbe3d950c9eeef00bf83d7602368840941dd92c6bb63b62c69994d5d9 927936 zabbix_7.0.29+dfsg.orig-vendor.tar.xz
 6dc16f00d67acb07aec7446d2e9994c7d64607539be8ab138bdf59b05b7aa4c1 22849540 zabbix_7.0.29+dfsg.orig.tar.xz
 e1f0fd056cb1debac1dbe2152535edd990bf6867e8892fcc4f0b90a19a2e1336 145456 zabbix_7.0.29+dfsg-1.debian.tar.xz
 99ded5a26d6cd3f9e34878074fbafe342feeb457acafc71e6530ed24dfd0ed4e 20929 zabbix_7.0.29+dfsg-1_amd64.buildinfo
Files:
 36849fb662505bbd80c0df982ce3d4b7 4216 net optional zabbix_7.0.29+dfsg-1.dsc
 a32f84021390c471b4773e7873d099b4 13682504 net optional zabbix_7.0.29+dfsg.orig-templates.tar.xz
 27f0fa78ec90f4ef7f2e85d0aab9201d 927936 net optional zabbix_7.0.29+dfsg.orig-vendor.tar.xz
 85ff4005f0eb9b20e2157c6af2b8154f 22849540 net optional zabbix_7.0.29+dfsg.orig.tar.xz
 8e1f8620dbb6e3e0dbfe0e9d2a74eac2 145456 net optional zabbix_7.0.29+dfsg-1.debian.tar.xz
 08598e691158f779ee1188fd2578c4d6 20929 net optional zabbix_7.0.29+dfsg-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEULx8+TnSDCcqawZWUra72VOWjRsFAmqKbVwACgkQUra72VOW
jRsxNQ/+OIbPKh3jZRX7DF94pLVFZJRJ2KcSAum5/LsPPX0jHwjF49SGRyXAyxkM
LE0u/9B9rPk8fFauCjzn9YPc5z7MU7Zbam6KRY4kIGz30M8icN+/9oQ72vE2pO1/
W28sBS4AgMcjfzi4GFCWvQMiHA6A23eqkGKvXdn81Zwrg7hPkhZYiTaZX4OTRYuq
SCBSqe+TiRXbG8TEVJVPMGh8vAreWFdB7lmsTP405FeLw9qo+di3nTDbMyEP0zXb
Zh5mCXQ0sBOJPlrHFqVkCGFsiqLJwtWBDyZ90Co7L3h27jyQ7pdif+QFAL7pXEbK
wjNtJpKsDTg1bfxUZGXmsreh2lX+naKsTLAZuFZEt2rTxhnFV6HtRK0zPbTvU88z
kfxPH6G2oxFJfwCHYK2ZiebSdDi4mWEhguiDBQL11Rt058kY+sTJKdi7JghWlVAl
l1bQaCs9ue8avjw5IsmK7YAC11gAiK9O+I0+p/gZCnKRv0k3UvHIncahjCFPU9iQ
ifBoBQlc9siHL+spCU6pg3iwTxn8NP8ALK1gobbRNdj1mjZPjF3KkkhLKMQQmb0/
PJCrtQj194TKQWmLDucn9hqRyt1/5n8tclOJzDvDpqWwNnMVLO3m+7s8Jfqs8bn1
wCbppq+2ShnEYDfb6zOUfDlqz8jmv2CFC7b+CUjS9QVYbLjEF1Y=
=8ooQ
-----END PGP SIGNATURE-----