Cross-site scripting in Zabbix - CVE-2026-23926

 

Cross-site scripting in Zabbix - CVE-2026-23926

Published: May 6, 2026


Vulnerability identifier: #VU130255
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-23926
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform unauthorized actions.

The vulnerability exists due to cross-site scripting in the Host navigator widget maintenance tooltip when rendering a maintenance period tooltip. A remote privileged user can create a maintenance period with a malicious JavaScript payload to perform unauthorized actions.

User interaction is required to open the tooltip for the crafted maintenance period in the Host navigator widget.


Affected software

Zabbix

How to mitigate CVE-2026-23926

Install security update from vendor's website.

Zabbix - addressed in versions 7.0.24, 7.4.8

External References

Related Security Bulletins