CVE-2026-23930

An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service.

Credits

Zabbix wants to thank barume for submitting this report on the HackerOne bug bounty platform.

References