
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23938 is a Denial of Service vulnerability in Zabbix server and proxy, where an authenticated administrator can crash the server or proxy by creating specially crafted JavaScript scripts in preprocessing or script item configurations. It affects Zabbix versions 6.0.0–6.0.46, 7.0.0–7.0.26, and 7.4.0–7.4.10. The vulnerability was disclosed on August 18, 2026, and assigned a CVSS v4.0 base score of 2.1 (Low) (Zabbix Bug Tracker, Red Hat Bugzilla).
The vulnerability is classified under CWE-248 (Uncaught Exception) and CWE-770 (Allocation of Resources Without Limits or Throttling), indicating that the Zabbix JavaScript preprocessing engine fails to properly handle or constrain malformed or resource-exhausting scripts. An authenticated administrator crafts a malicious JavaScript payload within a preprocessing step or script item, which when executed by the Zabbix server or proxy causes an unhandled exception or resource exhaustion, leading to a crash. Exploitation requires a network-accessible Zabbix instance and a valid administrator (non-super admin) account, as well as specific attack conditions (AT:P in the CVSS vector) (Zabbix Bug Tracker, Red Hat Bugzilla).
Successful exploitation results in a crash of the Zabbix server or proxy process, causing a denial of service and making monitoring infrastructure unavailable. The impact is limited to availability — there is no confidentiality or integrity impact — and affects only the Zabbix server or proxy component rather than underlying host systems. Service disruption could result in blind spots in infrastructure monitoring until the service is manually restarted (Zabbix Bug Tracker).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date. The vulnerability is not automatable and requires authenticated administrator-level access, significantly limiting the attacker pool. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (Red Hat Advisory, EUVD).
/var/log/zabbix/zabbix_server.log or zabbix_proxy.log, particularly around JavaScript preprocessing execution.zabbix_server or zabbix_proxy process without a graceful shutdown signal.Zabbix has released fixed versions addressing this vulnerability: 6.0.47, 7.0.27, and 7.4.11. Users should upgrade to the respective fixed version for their branch as the primary remediation. As an interim measure, restrict administrator privileges to only trusted users and monitor for unusual preprocessing or script item modifications. No specific configuration-based workaround is documented by the vendor (Zabbix Bug Tracker, Red Hat Bugzilla).
The vulnerability was reported to Zabbix via the HackerOne bug bounty platform by a researcher identified as "mjlx" and was acknowledged by the Zabbix team. Red Hat has tracked the issue in their security response system. No significant broader media coverage or notable community commentary has been observed, consistent with the low severity rating and limited exploitability of the vulnerability (Zabbix Bug Tracker, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."