Cross-site scripting in Zabbix - CVE-2026-23928
Published: May 6, 2026
Zabbix
Zabbix
Description
The vulnerability allows a remote user to perform unauthorized actions.
The vulnerability exists due to cross-site scripting in the Item history/Plain text widget when rendering monitored host data with HTML display enabled. A remote privileged user can send a malicious JavaScript payload from a controlled monitored host to perform unauthorized actions.
User interaction is required, and exploitation occurs when a user opens a dashboard containing the affected widget.