Zabbix: The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. (CVE-2026-23922)
Description
A vulnerability in Zabbix allows a Super Admin to leak the OAuth 'Client secret' by setting a malicious 'Token endpoint'. Although the 'Client secret' field cannot be read after saving, this flaw enables potential leakage through manipulation of the token endpoint. Changes have been made to reset the client secret when the token endpoint is changed to mitigate this issue.
CVSS v3.1
Score 4.9medium
Affected software
pkg:deb/ubuntu/zabbix?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/zabbix?arch=source&distro=esm-apps/xenialpkg:deb/ubuntu/zabbix?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/zabbix?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/zabbix?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/zabbix?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Zabbix concerns the email media OAuth configuration where the 'Client secret' field is protected from direct reading after saving. However, a Super Admin user can exploit this by setting a malicious 'Token endpoint' URL, which can lead to leakage of the client secret. To address this, the software was updated to reset the client secret whenever the token endpoint is changed, reducing the risk of secret exposure through this vector.
Potential Impact
The vulnerability allows a Super Admin to potentially leak the OAuth client secret by manipulating the token endpoint. This could compromise the confidentiality of the client secret, but does not affect integrity or availability. The CVSS score of 4.9 (medium severity) reflects the need for high privileges (Super Admin) to exploit and the limited scope of impact to confidentiality only.
Mitigation Recommendations
A fix is available that resets the client secret upon changing the token endpoint, preventing leakage via this method. Users should apply the updated versions of Zabbix that include this change. Since the vulnerability requires Super Admin privileges, limiting such privileges and applying the patch will mitigate the risk effectively.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-23922
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:26.04:LTS"]
- Cvss Version
- 4.0
Threat ID: 6a870a6facd9273b49b589cb
Added to database: 08/20/2026, 14:08:47 UTC
Last enriched: 09/10/2026, 14:41:30 UTC
Last updated: 10/05/2026, 06:48:15 UTC
Views: 34
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.