The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.
Credits
Zabbix wants to thank nidomer1 for submitting this report on the HackerOne bug bounty platform.