CVE Watchtower ← Back to CVE ListCVE-2026-23931NVDVulnerability SummaryThe frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.Severity LevelUNKNOWNPublished DateAug 18, 2026Last ModifiedAug 18, 2026Exploitation StatusNo confirmed exploitation yetEPSS Score (30-Day)Data PendingRoot Weakness (CWE)N/AExternal Referenceshttps://support.zabbix.com/browse/ZBX-28070