High SEVERITY — Vulnerability

CVE-2026-23926 — An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by

An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.

Platform
Zabbix
CVE Record
CVE-2026-23926
CVSS Score
7.3/10
Published
06 May 2026
Views
19
Primary source: Review the official advisory at nvd.nist.gov Go to Source

Summary

An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.

Assessment

  • CVE: CVE-2026-23926
  • CVSS base score: 7.3
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Source: NVD record

References

Action

  • Verify affected systems against your inventory
  • Apply the vendor patch during a maintenance window
  • Restrict access at the network layer until patched

Zabbix — Related Advisories

VIEW ALL →