Description
Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent simultaneously, potentially allowing for more password guesses than intended.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update the affected components to their respective fixed versions.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://support.zabbix.com/browse/ZBX-28076 |
|
History
Tue, 18 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent simultaneously, potentially allowing for more password guesses than intended. | |
| Title | API and Frontend login lockout race condition | |
| Weaknesses | CWE-362 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Zabbix
Published:
Updated: 2026-08-18T13:35:41.648Z
Reserved: 2026-01-19T14:02:49.454Z
Link: CVE-2026-1199
No data.
Status : Received
Published: 2026-08-18T13:17:20.900
Modified: 2026-08-18T13:17:20.900
Link: CVE-2026-1199
No data.
OpenCVE Enrichment
No data.
Weaknesses