CVE-2026-23919

CVE-2026-23919 is a medium-severity vulnerability in Zabbix with a CVSS 3.x base score of 6.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-488.

Key facts

Description

For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A fix has been released that makes the built in Zabbix JavaScript objects read-only, but please be advised that usage of global JavaScript variables is not recommended because their content could be leaked. More information <a href='https://www.zabbix.com/documentation/7.4/en/manual/installation/known_issues#preprocessing-global-variables-are-unsafe'>in Zabbix documentation</a>.

Frequently asked questions

What is CVE-2026-23919?
For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A fix has been released that makes the built in Zabbix JavaScript objects read-only, but please be advised that usage of global JavaScript variables is not recommended because their content could be leaked. More information <a href='https://www.zabbix.com/documentation/7.4/en/manual/installation/known_issues#preprocessing-global-variables-are-unsafe'>in Zabbix documentation</a>.
How severe is CVE-2026-23919?
CVE-2026-23919 has a CVSS 3.x base score of 6.0, rated medium severity. It is exploitable over network with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is high, integrity low, and availability low.
Is CVE-2026-23919 being actively exploited?
It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (14th percentile), an estimate of the probability of exploitation in the next 30 days.
What products are affected by CVE-2026-23919?
CVE-2026-23919 affects Zabbix. See the affected-products list for the exact vulnerable versions.
How do I fix CVE-2026-23919?
Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
Does CVE-2026-23919 have an EU (EUVD) identifier?
Yes. CVE-2026-23919 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-14950.
When was CVE-2026-23919 published?
CVE-2026-23919 was published on 2026-03-24 and last updated on 2026-09-18.

References

Affected products (1)

More vulnerabilities in Zabbix

All CVEs affecting Zabbix →

Other CWE-488 vulnerabilities

Browse all CWE-488 vulnerabilities →