CVE-2026-23938
Zabbix Server vulnerability analysis and mitigation

Overview

CVE-2026-23938 is a Denial of Service vulnerability in Zabbix server and proxy, where an authenticated administrator can crash the server or proxy by creating specially crafted JavaScript scripts in preprocessing or script item configurations. It affects Zabbix versions 6.0.0–6.0.46, 7.0.0–7.0.26, and 7.4.0–7.4.10. The vulnerability was disclosed on August 18, 2026, and assigned a CVSS v4.0 base score of 2.1 (Low) (Zabbix Bug Tracker, Red Hat Bugzilla).

Technical details

The vulnerability is classified under CWE-248 (Uncaught Exception) and CWE-770 (Allocation of Resources Without Limits or Throttling), indicating that the Zabbix JavaScript preprocessing engine fails to properly handle or constrain malformed or resource-exhausting scripts. An authenticated administrator crafts a malicious JavaScript payload within a preprocessing step or script item, which when executed by the Zabbix server or proxy causes an unhandled exception or resource exhaustion, leading to a crash. Exploitation requires a network-accessible Zabbix instance and a valid administrator (non-super admin) account, as well as specific attack conditions (AT:P in the CVSS vector) (Zabbix Bug Tracker, Red Hat Bugzilla).

Impact

Successful exploitation results in a crash of the Zabbix server or proxy process, causing a denial of service and making monitoring infrastructure unavailable. The impact is limited to availability — there is no confidentiality or integrity impact — and affects only the Zabbix server or proxy component rather than underlying host systems. Service disruption could result in blind spots in infrastructure monitoring until the service is manually restarted (Zabbix Bug Tracker).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date. The vulnerability is not automatable and requires authenticated administrator-level access, significantly limiting the attacker pool. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (Red Hat Advisory, EUVD).

Exploitation steps

  1. Obtain Administrator Access: Gain access to a Zabbix administrator (non-super admin) account through credential theft, phishing, or reuse of compromised credentials.
  2. Navigate to Preprocessing or Script Items: Log into the Zabbix web frontend and navigate to Configuration > Hosts/Templates > Items, then create or edit an item with a preprocessing step of type "JavaScript" or a Script-type item.
  3. Craft Malicious JavaScript: Insert a specially crafted JavaScript payload designed to trigger an uncaught exception or exhaust resources (e.g., infinite loops, deeply recursive functions, or excessively large data allocations) within the script body.
  4. Save and Trigger Execution: Save the item configuration. The Zabbix server or proxy will execute the JavaScript during the next data collection cycle, causing a crash and denial of service (Zabbix Bug Tracker).

Indicators of compromise

  • Logs: Unexpected Zabbix server or proxy crash entries in /var/log/zabbix/zabbix_server.log or zabbix_proxy.log, particularly around JavaScript preprocessing execution.
  • Process: Sudden termination of the zabbix_server or zabbix_proxy process without a graceful shutdown signal.
  • Configuration: Newly created or recently modified preprocessing items or script items containing unusual or obfuscated JavaScript code, especially those created by administrator accounts not typically involved in item configuration.
  • Audit Logs: Zabbix audit log entries showing administrator account activity creating or modifying script/preprocessing items shortly before service crashes (Zabbix Bug Tracker).

Mitigation and workarounds

Zabbix has released fixed versions addressing this vulnerability: 6.0.47, 7.0.27, and 7.4.11. Users should upgrade to the respective fixed version for their branch as the primary remediation. As an interim measure, restrict administrator privileges to only trusted users and monitor for unusual preprocessing or script item modifications. No specific configuration-based workaround is documented by the vendor (Zabbix Bug Tracker, Red Hat Bugzilla).

Community reactions

The vulnerability was reported to Zabbix via the HackerOne bug bounty platform by a researcher identified as "mjlx" and was acknowledged by the Zabbix team. Red Hat has tracked the issue in their security response system. No significant broader media coverage or notable community commentary has been observed, consistent with the low severity rating and limited exploitability of the vulnerability (Zabbix Bug Tracker, Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related Zabbix Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23935MEDIUM6.8
  • Zabbix Server logoZabbix Server
  • zabbix
NoNoAug 18, 2026
CVE-2026-23937MEDIUM6
  • Zabbix Server logoZabbix Server
  • zabbix
NoNoAug 18, 2026
CVE-2026-59781MEDIUM5.4
  • Zabbix Server logoZabbix Server
  • zabbix
NoNoAug 18, 2026
CVE-2026-23934MEDIUM5.1
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoNoAug 18, 2026
CVE-2026-23938LOW2.1
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoNoAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management