CVE-2026-23926Medium· 6.8▾ SunlitAn authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.
zabbix >= 7.0.0, < 7.0.24zabbix >= 7.4.0, < 7.4.8Upgrade past the affected range:
zabbix 7.4.8Connected by shared product, vendor, weakness, or advisory.
CVE-2026-23928Medium· 6.8The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled
CVE-2026-23924Medium· 4.9Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon
CVE-2026-23919Medium· 6.0For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks)
CVE-2026-23927Medium· 6.5A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter
CVE-2026-23923Medium· 5.3An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes
CVE-2026-23921High· 8.8A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter