---
id: CVE-2026-23926
title: >-
  An authenticated (non-super) administrator can create a maintenance period
  with a JavaScript payload that is executed by any user that opens tooltip for
  that maintenance period in the Host navigator widget
summary: >-
  An authenticated (non-super) administrator can create a maintenance period
  with a JavaScript payload that is executed by any user that opens tooltip for
  that maintenance period in the Host navigator widget. This can allow the
  attacker to…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
vendor: zabbix
product: zabbix
affected:
  - 'zabbix >= 7.0.0, < 7.0.24'
  - 'zabbix >= 7.4.0, < 7.4.8'
patched:
  - zabbix 7.4.8
published: '2026-05-06'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T15:35:11.087'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-23926'
references:
  - url: 'https://support.zabbix.com/browse/ZBX-27758'
    label: security@zabbix.com
tags:
  - nvd
epss: 0.00263
epssPercentile: 0.18437
ingestedAt: '2026-09-18T15:44:31.550Z'
---

## Overview

An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.

## Affected

- `zabbix >= 7.0.0, < 7.0.24`
- `zabbix >= 7.4.0, < 7.4.8`

## Remediation

Upgrade past the affected range:

- `zabbix 7.4.8`
