VDB

GCVE-110-NCSC-2026-320

GCVE-110-NCSC-2026-320
Advisory PublishedCVSS 2.7/10
Vulnetix · Advisory published August 20, 2026
The Zabbix API and Frontend login lockout mechanism contains a vulnerability where simultaneous failed login attempts are not properly counted, allowing attackers to potentially exceed intended password guess limits.

Weaknesses (CWE)

CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')CWE-522Insufficiently Protected CredentialsCWE-1321Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')CWE-405Asymmetric Resource Consumption (Amplification)CWE-203Observable DiscrepancyCWE-259Use of Hard-coded PasswordCWE-125Out-of-bounds ReadCWE-248Uncaught ExceptionCWE-427Uncontrolled Search Path Element

Risk Scores

CVSS 3.1
2.7/10
Low · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

Affected Products

VendorProductVersionsPlatforms
Zabbixvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

3,530 records in the GCVE database · Updated September 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›