Cross-site scripting in Zabbix - CVE-2026-59788
Published: October 5, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in a Super Admin's browser.
The vulnerability exists due to improper validation of URL schemes in the email media type OAuth configuration form when a Super Admin opens an attacker-supplied media type import file. A remote privileged user can provide a crafted media type configuration to execute arbitrary JavaScript in a Super Admin's browser.