Back

MEDIUM

Unauthenticated arbitrary PHP class instantiation

Published Mar 24, 2026

Description

An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.

Affected products

Remediation

Vendor solution

Update the affected components to their respective fixed versions.

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Zabbix
Published Mar 24, 2026
Updated Mar 25, 2026
Reserved Jan 19, 2026
CISA Vulnrichment
Updated Mar 25, 2026
NVD
Status Analyzed
Modified Sep 10, 2026
Red Hat
Severity n/a
Public date n/a