
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23935 is a use-after-free out-of-bounds read vulnerability in Zabbix's script item/preprocessing (JavaScript) HttpRequest logic that allows an authenticated administrator to read out-of-bounds memory, leading to potential confidentiality loss. It affects Zabbix versions 7.0.0 through 7.0.27 and 7.4.0 through 7.4.11. The vulnerability was disclosed on August 18, 2026, and was reported via the HackerOne bug bounty platform by Aikido Security. It carries a CVSS v4.0 base score of 6.8 (Medium) (Zabbix Advisory).
The vulnerability is classified as CWE-125 (Out-of-bounds Read), specifically a use-after-free read condition in the HttpRequest body handling within Zabbix's script item and JavaScript preprocessing engine. An authenticated administrator can craft a malicious script item or JavaScript preprocessing script that triggers improper memory access in the HttpRequest logic, causing the server to read memory beyond the intended buffer boundaries. Exploitation requires adjacent network access, high privileges (administrator role), and no user interaction, limiting the attack surface but not eliminating risk in shared or multi-tenant Zabbix deployments (Zabbix Advisory).
Successful exploitation results in a confidentiality impact — specifically, the ability to read out-of-bounds memory from the Zabbix server process, which may expose sensitive data such as credentials, configuration values, or other in-memory secrets. There is no integrity or availability impact associated with this vulnerability. The scope is limited to the vulnerable component itself, with no lateral movement potential directly attributable to this flaw (Zabbix Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the disclosure date. The NVD SSVC assessment indicates exploitation is currently "none" and the vulnerability is not automatable. The EPSS score is 0.0, reflecting a very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated Zabbix administrator account, significantly limiting the attacker pool (Zabbix Advisory).
HttpRequest object with specifically crafted parameters designed to trigger the use-after-free condition in the server-side HttpRequest body handling logic.HttpRequest objects with anomalous parameters.zabbix_server.log) related to memory access violations or HttpRequest processing.zabbix_server process.HttpRequest with unusual body content.Zabbix has released fixed versions addressing this vulnerability: 7.0.28 (for the 7.0.x branch) and 7.4.12 (for the 7.4.x branch). No workarounds are available; the vendor recommends updating to the respective fixed versions as the sole mitigation. Organizations should also enforce the principle of least privilege for Zabbix administrator accounts to reduce the risk of exploitation (Zabbix Advisory).
The vulnerability was discovered and reported by Aikido Security through the HackerOne bug bounty program, and Zabbix acknowledged the submission. No significant public commentary, media coverage, or social media discussion has been observed beyond the initial disclosure (Zabbix Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."