Use-after-free in Zabbix - CVE-2026-23935
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote privileged user to disclose sensitive information.
The vulnerability exists due to use-after-free in script item/preprocessing HttpRequest body logic when processing specifically crafted script items or JavaScript preprocessing scripts. A remote privileged user can create a specially crafted script item or JavaScript preprocessing script to disclose sensitive information.
The issue affects the server component.