{"id":"CVE-2026-23928","title":"The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled","summary":"The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a da…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-79"],"vendor":"zabbix","product":"zabbix","affected":["zabbix >= 6.0.0, < 6.0.45","zabbix >= 7.0.0, < 7.0.24","zabbix >= 7.4.0, < 7.4.8"],"patched":["zabbix 7.4.8"],"published":"2026-05-06","updated":"2026-09-18","sourceUpdated":"2026-09-18T15:19:05.330","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-23928","references":[{"url":"https://support.zabbix.com/browse/ZBX-27760","label":"security@zabbix.com"}],"tags":["nvd"],"epss":0.00263,"epssPercentile":0.18431,"ingestedAt":"2026-09-18T15:44:31.552Z","slug":"CVE-2026-23928","body":"## Overview\n\nThe Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.\n\n## Affected\n\n- `zabbix >= 6.0.0, < 6.0.45`\n- `zabbix >= 7.0.0, < 7.0.24`\n- `zabbix >= 7.4.0, < 7.4.8`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `zabbix 7.4.8`","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}