Cross-site scripting in Zabbix - CVE-2026-23928
Published: May 6, 2026
Vulnerability details
The vulnerability allows a remote user to perform unauthorized actions.
The vulnerability exists due to cross-site scripting in the Item history/Plain text widget when rendering monitored host data with HTML display enabled. A remote privileged user can send a malicious JavaScript payload from a controlled monitored host to perform unauthorized actions.
User interaction is required, and exploitation occurs when a user opens a dashboard containing the affected widget.
Affected software
Fedora
zabbix6.0
zabbix7.0
How to mitigate CVE-2026-23928
zabbix6.0 - update to 6.0.46-1.el8
zabbix7.0 - addressed in versions 7.0.26-1.el8, 7.0.26-1.el10_1, 7.0.26-1.el10_2, 7.0.26-1.el10_3