CVE-2026-23935
Zabbix Server vulnerability analysis and mitigation

Overview

CVE-2026-23935 is a use-after-free out-of-bounds read vulnerability in Zabbix's script item/preprocessing (JavaScript) HttpRequest logic that allows an authenticated administrator to read out-of-bounds memory, leading to potential confidentiality loss. It affects Zabbix versions 7.0.0 through 7.0.27 and 7.4.0 through 7.4.11. The vulnerability was disclosed on August 18, 2026, and was reported via the HackerOne bug bounty platform by Aikido Security. It carries a CVSS v4.0 base score of 6.8 (Medium) (Zabbix Advisory).

Technical details

The vulnerability is classified as CWE-125 (Out-of-bounds Read), specifically a use-after-free read condition in the HttpRequest body handling within Zabbix's script item and JavaScript preprocessing engine. An authenticated administrator can craft a malicious script item or JavaScript preprocessing script that triggers improper memory access in the HttpRequest logic, causing the server to read memory beyond the intended buffer boundaries. Exploitation requires adjacent network access, high privileges (administrator role), and no user interaction, limiting the attack surface but not eliminating risk in shared or multi-tenant Zabbix deployments (Zabbix Advisory).

Impact

Successful exploitation results in a confidentiality impact — specifically, the ability to read out-of-bounds memory from the Zabbix server process, which may expose sensitive data such as credentials, configuration values, or other in-memory secrets. There is no integrity or availability impact associated with this vulnerability. The scope is limited to the vulnerable component itself, with no lateral movement potential directly attributable to this flaw (Zabbix Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the disclosure date. The NVD SSVC assessment indicates exploitation is currently "none" and the vulnerability is not automatable. The EPSS score is 0.0, reflecting a very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated Zabbix administrator account, significantly limiting the attacker pool (Zabbix Advisory).

Exploitation steps

  1. Gain Administrator Access: Obtain valid Zabbix administrator credentials through phishing, credential stuffing, or insider access — required since exploitation demands high privileges.
  2. Access Script Item or Preprocessing Configuration: Navigate to the Zabbix web frontend and create or modify a script item or a JavaScript preprocessing step on an existing item.
  3. Craft Malicious HttpRequest Script: Write a JavaScript script that leverages the HttpRequest object with specifically crafted parameters designed to trigger the use-after-free condition in the server-side HttpRequest body handling logic.
  4. Execute the Script: Save and trigger the item or preprocessing step, causing the Zabbix server to process the malicious script and read out-of-bounds memory.
  5. Retrieve Leaked Memory: Observe the output or error responses from the script execution to extract potentially sensitive data from the server's memory space (Zabbix Advisory).

Indicators of compromise

  • Logs: Zabbix server logs showing unusual or repeated execution of script items or JavaScript preprocessing steps by an administrator account, particularly those involving HttpRequest objects with anomalous parameters.
  • Logs: Unexpected errors or crashes in the Zabbix server log (zabbix_server.log) related to memory access violations or HttpRequest processing.
  • Process: Abnormal memory usage or segmentation fault signals from the zabbix_server process.
  • File System: New or recently modified script items or JavaScript preprocessing configurations in the Zabbix database that reference HttpRequest with unusual body content.

Mitigation and workarounds

Zabbix has released fixed versions addressing this vulnerability: 7.0.28 (for the 7.0.x branch) and 7.4.12 (for the 7.4.x branch). No workarounds are available; the vendor recommends updating to the respective fixed versions as the sole mitigation. Organizations should also enforce the principle of least privilege for Zabbix administrator accounts to reduce the risk of exploitation (Zabbix Advisory).

Community reactions

The vulnerability was discovered and reported by Aikido Security through the HackerOne bug bounty program, and Zabbix acknowledged the submission. No significant public commentary, media coverage, or social media discussion has been observed beyond the initial disclosure (Zabbix Advisory).

Additional resources


SourceThis report was generated using AI

Related Zabbix Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23935MEDIUM6.8
  • Zabbix Server logoZabbix Server
  • zabbix
NoNoAug 18, 2026
CVE-2026-23937MEDIUM6
  • Zabbix Server logoZabbix Server
  • zabbix
NoNoAug 18, 2026
CVE-2026-59781MEDIUM5.4
  • Zabbix Server logoZabbix Server
  • zabbix
NoNoAug 18, 2026
CVE-2026-23934MEDIUM5.1
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoNoAug 18, 2026
CVE-2026-23938LOW2.1
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoNoAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management